Troy Hunt posts 23,272,765 Paidwork users exposed, including bank details and bcrypt hashes
A microtask platform breach added to Have I Been Pwned reveals far more than emails, from bank numbers to payouts.

Troy Hunt’s Have I Been Pwned added alleged Paidwork breach data on July 19, covering 23,272,765 users. For decision-makers, the incident shows how gig-economy workflows can turn personal and financial data into a ready-made fraud supply chain.
More than 23 million people who signed up to earn money from online microtasks may now have their personal and financial information exposed. According to Troy Hunt’s Have I Been Pwned listing, the alleged breach affects 23,272,765 users and was traced back to an intrusion in March. The entry went live on July 19, after a database believed to be stolen from Paidwork was publicly released earlier this month.
Here is what makes this more than a routine data leak: the Troy Hunt listing reports exposed information that goes well beyond names and email addresses. The dataset reportedly includes bank account numbers, phone numbers, physical addresses, dates of birth, profile photographs, IP addresses, device information, and financial transaction records, including payout histories and even passwords stored as bcrypt hashes. Bcrypt is designed to make password cracking significantly harder than older hashing schemes, but it does not magically eliminate risk, because weak passwords may still be recoverable.
The alleged breach did not just appear out of nowhere. The database first surfaced in April when someone using the handle "HACKFORMETOME" advertised an 11 GB dump from Paidwork’s production systems on a popular cybercrime forum. That seller claimed the database contained records for more than 22 million users and tried to auction it through Telegram and Tox. Paidwork itself had not publicly acknowledged the alleged breach at the time of writing, and The Register reports it asked the company to confirm the authenticity of the leaked data and describe what steps it had taken to notify affected users, but the company did not immediately respond.
If you run or invest in platforms that rely on microtasks, cash-out thresholds, or payouts, this incident is a flashing sign. Paidwork markets itself as a way to earn money through small online tasks like playing mobile games, watching advertisements, completing surveys, testing apps, shopping through cashback offers, and referring other users. Most individual jobs pay only a few cents, and workers must earn at least $10 before cashing out. That $10 minimum and the “earn and withdraw” workflow are exactly the kind of systems that require sensitive data collection, and once attackers get a foothold, they can monetize it in ways that do not require advanced hacking. When the leak includes bank account numbers and payout histories, it helps criminals target victims with timing and credibility.
From a risk standpoint, the database content reads like a complete identity and payment dossier, not just a contact list. The listing reportedly includes education levels, financial transaction records, and payout histories, which can help fraudsters craft more convincing scams and impersonation attempts. It also includes passwords stored as bcrypt hashes. Bcrypt raises the bar for cracking, but the Register notes that weak passwords could still be recovered. That matters because password habits in consumer-facing platforms are rarely perfect, and reused passwords are common. Even if bcrypt prevents easy cracking of every password, a subset of users still becomes vulnerable, and attackers can then use other data fields to expand the damage.
There is also a second-order business implication that boards and executives should not ignore: when breaches hit identity-plus-financial-data, the operational burden shifts from “incident response” to “ongoing victim support.” The source urges anyone who reused their password elsewhere to change it immediately, keep an eye on financial accounts, and be alert for phishing emails built from the trove of personal information now circulating online. That is not just consumer advice. It is the real cost center that emerges after the initial breach headlines fade, as affected users take time to monitor accounts, as support teams get flooded, and as regulators and partners ask whether enough was done quickly enough.
On the regulatory and reputational front, the timeline is worth a hard look. The intrusion is traced back to March, the database surfaced in April on a cybercrime forum with claims of an 11 GB production-system dump, and then the data was added to Have I Been Pwned on July 19 after public release earlier this month. The speed between “production systems allegedly compromised” and “breach appears in a widely used breach-checking service” is the kind of gap that invites scrutiny. Even when a company does not publicly acknowledge a breach immediately, the market reality is that third-party breach repositories can do the communicating for you.
For executives at adjacent microtask, gig, and fintech-adjacent platforms, the strategic stakes are blunt: the combination of user incentives, payout processes, and broad data collection can turn a cyber incident into a fraud enabler at scale. This is the part where cyber teams and product teams need to share the same map. The dataset reported by Have I Been Pwned includes the credentials and the payment context attackers need to go from “data stolen” to “money attempted.” If you are building systems where users earn and cash out, the lesson is not just about encryption and hashing. It is about minimizing exposure, validating incident authenticity quickly, and being ready for the day when your users’ financial lives become part of the breach news cycle.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.

SK Hynix opens at $170, raises $26.5B, and tops foreign IPO records
In Friday's Wall Street debut, SK Hynix turns AI RAM demand into a $26.5B fundraising moment that rewrites comps.

