2 min read

Paidwork breach allegedly exposes 23 million users

An alleged Paidwork breach exposed data on 23.27 million users, including bank details, payout histories, personal information, and bcrypt passwords.

Image: The Register

More than 23 million Paidwork users may have had their personal and financial data exposed after an allegedly stolen database was released online. Troy Hunt’s Have I Been Pwned (HIBP) added the incident on July 19, tracing the breach to an intrusion in March.

HIBP says the database contains records belonging to 23,272,765 users. The alleged breach first surfaced in April, when a person using the handle “HACKFORMETOME” advertised an 11 GB dump from Paidwork’s production systems on a cybercrime forum. The seller claimed it covered more than 22 million users and tried to auction the data through Telegram and Tox.

Data reportedly exposed

According to the HIBP listing, the information extends well beyond names and email addresses. It reportedly includes:

Recommended reading

Ostium loses $23.75 million in price-feed attack

  • Bank account numbers and financial transaction records
  • Payout histories, phone numbers, physical addresses, and dates of birth
  • Profile photographs, IP addresses, and device information
  • Education levels and passwords stored as bcrypt hashes

Bcrypt makes password cracking substantially harder than older hashing methods, but weak passwords can still be recovered. Paidwork had not publicly acknowledged the alleged breach when The Register published its report. The company was asked to verify the data and explain how it planned to notify affected users, but did not immediately respond.

Paidwork offers small online jobs such as playing mobile games, watching advertisements, completing surveys, testing apps, using cashback offers, and referring users. Individual tasks generally pay only a few cents, and users must earn at least $10 before withdrawing funds.

Anyone who reused a Paidwork password on another service should change it immediately. Users should also monitor financial accounts and treat unexpected messages with caution, particularly phishing attempts built from the exposed personal details.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via The Register

/ Keep reading