Infosec expert: Paidwork users’ data pwned after 23M-record database dumped online

← Back to the feed

Infosec expert: Paidwork users’ data pwned after 23M-record database dumped online

The Register · 2 months ago

More than 23 million users of microtask platform Paidwork have reportedly had their personal and financial data exposed after a stolen database was published online. The breach notification service Have I Been Pwned added the incident on 19 July, tracing it back to an intrusion said to have occurred in March, with the data first offered for sale on a cybercrime forum in April by a user calling themselves "HACKFORMETOME". Paidwork, which lets users earn small sums by completing tasks such as watching adverts, testing apps and taking surveys, has not publicly confirmed the breach and did not respond to a request for comment.

The leaked dataset reportedly covers 23,272,765 users and includes bank account numbers, phone numbers, physical addresses, dates of birth, profile photos, IP and device information, financial transaction records, payout histories, education levels, and passwords hashed with bcrypt. Although bcrypt is considerably harder to crack than older hashing methods, weak passwords remain vulnerable. Given the breadth of personal and financial detail exposed, affected users are being urged to change any reused passwords, monitor their financial accounts, and watch out for phishing attempts exploiting the leaked information.

  • Paidwork breach reportedly exposed data on 23.2 million users
  • Leak includes bank details, addresses, and bcrypt-hashed passwords
  • Paidwork has not confirmed the breach or responded to queries

New here? Start with this

Paidwork is an online "microtask" platform, a site where people complete small jobs such as watching adverts, testing apps or filling in surveys in exchange for small payments. It has an international user base of tens of millions of people, many of whom will have supplied personal details, bank information and identity documents to sign up and get paid.

According to reports, a database containing records for more than 23 million Paidwork users was stolen in an intrusion said to have taken place in March, then offered for sale on a cybercrime forum in April by someone using the name "HACKFORMETOME". The breach was later logged by Have I Been Pwned, a widely used service that lets people check whether their details have appeared in known data leaks. Paidwork itself has not confirmed the incident.

The story matters because the data reportedly involved goes well beyond email addresses, including bank account details, dates of birth, home addresses, photos and financial transaction histories, information that could be used for fraud or identity theft if it falls into the wrong hands. It is a useful case study in how breaches at smaller, less well-known platforms can still expose large volumes of sensitive personal and financial data.

Software

Read the full article at the source →