A threat actor claims to have breached WorkL and published a database containing account information, workplace records, device data and location information tied to users of the employee happiness and workplace intelligence platform.
The alleged database was posted on 18 Aug. 2026 and is described as containing several separate collections, including approximately 29,000 user accounts, 43,000 organization users, 65,000 registered devices, 150,000 survey company records, 71,000 company records and 392,000 user profiles.
Those figures represent more than 750,000 rows across the listed tables, although they should not be interpreted as 750,000 unique affected individuals because records may overlap between datasets.
Account passwords and location data appear in samples
The threat actor claims the compromised information includes email addresses, names, password hashes, phone numbers, company names, job titles, geolocation information and device details.
Samples accompanying the post appear to contain hashed passwords rather than plaintext credentials. The exposed fields also reportedly include account creation and update timestamps, organization associations, mobile device models, operating systems, geographic coordinates and other profile information.
BreachNews is not reproducing the leaked records or personal information contained in the samples.
Some records shown by the threat actor carry timestamps from 18 Aug. 2026, including records apparently created or updated shortly before the database was published. If authentic, those timestamps could indicate the dataset was obtained recently rather than originating exclusively from an older compromise.
WorkL holds data spanning employees and organizations
WorkL describes itself as a workplace intelligence platform that helps users measure workplace happiness, develop their careers and identify employers. Its platform says it draws on employee feedback and information covering more than 200,000 organizations.
The claimed breach is therefore notable for the range of information allegedly exposed. Beyond conventional account information, the purported dataset appears to include employment relationships, organization records, workplace survey-related data and user location information.
That combination could increase phishing and credential-theft risks if the material is authentic. Email addresses, employer information and job details can give attackers additional context for constructing targeted messages, while exposed password hashes could become a credential risk if weak passwords are successfully cracked and reused elsewhere.
Fresh timestamps add weight but not confirmation
The threat actor has made the database available for download and provided samples intended to support the breach claim. However, BreachNews has not independently verified that the complete dataset originated from WorkL or established how the information was allegedly obtained.
The presence of apparently recent records provides a potentially significant indicator, but database timestamps alone cannot establish that an unauthorized intrusion occurred or prove the provenance of the complete dataset.
WorkL had not issued any public statement concerning the alleged database leak at time of publication.











