The exposed database includes a broad range of personal and financial data :
Troy Hunt noted that about 35% of the email addresses were already in HIBP from previous breaches, and that the bcrypt-hashed passwords — while not plaintext — are the only field that attackers can realistically attempt to crack offline .
| Date | Event |
|---|---|
| March 2026 | Hackers claim to have obtained Paidwork's database and list it for sale on an underground forum |
| April 2, 2026 | Threat actor "hackformetome" posts the alleged database (22M+ records, 11 GB) on a major dark web forum |
| May 26, 2026 | The database is validated as a genuine production archive by breach monitoring services |
| Early July 2026 | The dataset is made publicly available |
| July 19, 2026 | HIBP adds the breach to its database; Mozilla Monitor also lists it |
The combination of financial and personal data in a single dump creates a dangerous set of attack vectors:
If you had a Paidwork account, take these actions immediately:
The Paidwork breach is a stark reminder that gig-economy platforms hold a rich mix of personal and financial data that is highly valuable to attackers. Because many of the exposed data types — such as bank account numbers and dates of birth — cannot be changed, the risk of fraud and phishing will persist for years. Acting quickly to secure your accounts and monitor your finances is the best defense.