Infosec expert: Paidwork users’ data pwned after 23M-record database dumped online

← Back to the feed

Infosec expert: Paidwork users’ data pwned after 23M-record database dumped online

The Register · 15 hours ago

More than 23 million users of microtask platform Paidwork have reportedly had their personal and financial data exposed after a stolen database was published online. The breach notification service Have I Been Pwned added the incident on 19 July, tracing it back to an intrusion said to have occurred in March, with the data first offered for sale on a cybercrime forum in April by a user calling themselves "HACKFORMETOME". Paidwork, which lets users earn small sums by completing tasks such as watching adverts, testing apps and taking surveys, has not publicly confirmed the breach and did not respond to a request for comment.

The leaked dataset reportedly covers 23,272,765 users and includes bank account numbers, phone numbers, physical addresses, dates of birth, profile photos, IP and device information, financial transaction records, payout histories, education levels, and passwords hashed with bcrypt. Although bcrypt is considerably harder to crack than older hashing methods, weak passwords remain vulnerable. Given the breadth of personal and financial detail exposed, affected users are being urged to change any reused passwords, monitor their financial accounts, and watch out for phishing attempts exploiting the leaked information.

  • Paidwork breach reportedly exposed data on 23.2 million users
  • Leak includes bank details, addresses, and bcrypt-hashed passwords
  • Paidwork has not confirmed the breach or responded to queries

Software

Read the full article at the source →