Paidwork Data Breach Exposes 23 Million User Records, HIBP Says
- Data breach: Hackers claim to have stolen data from the gig economy platform Paidwork in March, exposing over 23 million unique email addresses.
- Records exposed: Nearly 11GB of data was posted publicly in July 2026, including sensitive information.
- User data: The leak reportedly includes banking details, payout history, and bcrypt-hashed passwords.
Gig economy platform Paidwork has reportedly suffered a major data breach after hackers claimed to have obtained and sold platform data on March 23, 2026. The stolen dataset was subsequently released publicly in July and added to the breach notification service Have I Been Pwned (HIBP) on July 19.
The leaked archive totals almost 11GB and allegedly contains 23,272,76 unique email addresses tied to Paidwork users.
Nearly 11GB of Data Leaked Publicly
The exposed data reportedly spans a wide range of platform operations, including user profile information, banking details, and worker payout histories, according to HIBP. The Paidwork data breach allegedly exposed:
- Bank account numbers
- Dates of birth
- Device information
- Education levels
- Email addresses
- Financial transactions
- Genders
- IP addresses
- Names
- Passwords (bcrypt hashes)
- Personal interests
- Phone numbers
- Physical addresses
- Profile photos
Initially, the claims suggested that around 22 million addresses were stolen.
Passwords Stored as Bcrypt Hashes
According to HIBP, user passwords in the leaked dataset were stored as bcrypt hashes (highly resistant to modern brute-force attacks) rather than in plaintext. The combination of financial, personal, and behavioral data makes this breach notable for its breadth.
Was My Data in the Paidwork Breach?
However, the broader scope of compromised information raises significant privacy and security concerns for affected users. You can check whether you were impacted by entering the email you used with Paidwork on the HIBP website.
The Paidwork breach echoes previous gig-economy incidents, such as the 2016 Uber breach affecting roughly 57 million users and the 2019 DoorDash breach, though Paidwork's leak is notable for including full banking details and payout histories alongside standard contact information.






