Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Paidwork Breach Exposes Data on 23 Million Users. The Company Still Hasn't Said a Word

You sign up for a website that pays a few cents to watch ads or fill out surveys. In exchange, you hand over your name, home address, date of birth, bank account number, and a password. That's the deal millions of people made with Paidwork. Now that data is reportedly sitting on a criminal marketplace.
According to Have I Been Pwned, the breach-notification service run by security researcher Troy Hunt, the leaked database covers 23,272,765 user accounts. The service added the incident to its database on July 19, 2026, and lists the actual intrusion as having happened back in March 2026.
The timeline, pieced together by Malwarebytes and Help Net Security, shows a threat actor using the alias "hackformetome" first advertised the stolen data on a cybercrime forum in April, claiming it was an 11GB dump pulled straight from Paidwork's production systems. That listing claimed more than 22 million user records. The full database reportedly surfaced publicly in July, and researchers confirmed it held over 23 million unique email addresses.
This isn't just email addresses and throwaway passwords. According to Have I Been Pwned, Malwarebytes, and Help Net Security, the exposed data includes full names, phone numbers, home addresses, dates of birth, gender, and education levels. It also reportedly includes profile photos and personal interests.
Then there's the financial side. Bank account numbers, transaction records, and payout histories are reportedly part of the haul, according to all three cybersecurity outlets. Device and IP information is in there too, which can reveal what equipment someone used to log in and from where.
Passwords were stored as bcrypt hashes, which is a stronger method than plaintext or weaker hashing algorithms. But Have I Been Pwned's own guidance notes that bcrypt doesn't make weak or reused passwords immune to cracking. If you used the same password on Paidwork as on your email or banking accounts, the exposure runs deeper.
Accountability gets murky here. Fox News reported that Paidwork told its CyberGuy tech contributor Kurt Knutsson the company is "actively investigating the reported breach, working with external security specialists and taking steps to protect affected accounts and notify users as appropriate."
That statement, however, stands in contrast to what Malwarebytes and Help Net Security found as of their reporting: no public acknowledgment from Paidwork, and no evidence of direct notification to affected users. Class Action U, which is soliciting potential plaintiffs for a lawsuit, states plainly that "as of this writing, Paidwork has not issued any public acknowledgment or official statement regarding the breach, and no formal notification appears to have been sent directly to affected users through the company itself."
So either Paidwork gave Fox News a private response it hasn't extended publicly to the 23 million people whose bank details are floating around a hacker forum, or the company's outreach has been limited enough that three separate cybersecurity outlets missed it entirely. Either way, if you had a Paidwork account, you should not wait for the company to tell you something went wrong.
Have I Been Pwned's standard advice applies directly here. Change your Paidwork password immediately, and change it anywhere else you reused it. Turn on two-factor authentication wherever it's offered. Use a password manager so you're not reusing credentials across a dozen sites in the first place.
Given that bank account numbers and transaction histories are reportedly in the leak, anyone who used Paidwork should also watch their bank statements closely for unfamiliar activity and consider a fraud alert with the major credit bureaus.
There's a broader lesson in here that both Malwarebytes and Help Net Security hit on. People treat low-stakes gig apps as low-risk because the payouts are small, a few cents per survey or ad view. But the data these platforms collect—full legal name, date of birth, bank routing numbers—is exactly what identity thieves want. The size of your paycheck has nothing to do with the size of your exposure.
No government regulator has announced an investigation into Paidwork as of this writing, and no charges have been filed against anyone connected to the breach. The class-action effort tracked by Class Action U is still in the eligibility-screening stage, not a filed judgment. Whether Paidwork faces any formal penalty, and whether it ever issues the direct user notifications that data-breach laws in most states require, remains an open question for the 23 million people waiting to hear if their bank details are the next thing to get drained.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.