• 2 min read
Paidwork breach allegedly exposes 23 million users
An alleged Paidwork breach exposed data on 23.27 million users, including bank details, payout histories, personal information, and bcrypt passwords.

Image: The Register
More than 23 million Paidwork users may have had their personal and financial data exposed after an allegedly stolen database was released online. Troy Hunt’s Have I Been Pwned (HIBP) added the incident on July 19, tracing the breach to an intrusion in March.
HIBP says the database contains records belonging to 23,272,765 users. The alleged breach first surfaced in April, when a person using the handle “HACKFORMETOME” advertised an 11 GB dump from Paidwork’s production systems on a cybercrime forum. The seller claimed it covered more than 22 million users and tried to auction the data through Telegram and Tox.
Data reportedly exposed
According to the HIBP listing, the information extends well beyond names and email addresses. It reportedly includes:

Recommended reading
Ostium loses $23.75 million in price-feed attack
- Bank account numbers and financial transaction records
- Payout histories, phone numbers, physical addresses, and dates of birth
- Profile photographs, IP addresses, and device information
- Education levels and passwords stored as bcrypt hashes
Bcrypt makes password cracking substantially harder than older hashing methods, but weak passwords can still be recovered. Paidwork had not publicly acknowledged the alleged breach when The Register published its report. The company was asked to verify the data and explain how it planned to notify affected users, but did not immediately respond.
Paidwork offers small online jobs such as playing mobile games, watching advertisements, completing surveys, testing apps, using cashback offers, and referring users. Individual tasks generally pay only a few cents, and users must earn at least $10 before withdrawing funds.
Anyone who reused a Paidwork password on another service should change it immediately. Users should also monitor financial accounts and treat unexpected messages with caution, particularly phishing attempts built from the exposed personal details.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via The Register


