Menu
Browse

Cyber Incident Victim: Paidwork

Date:

Mar 2026

Location:

Summary

Paidwork disclosed that a threat actor leaked an 11 GB database allegedly containing information of roughly 22 million users, with analysis showing 23.3 million unique email addresses alongside names, password hashes, physical addresses, dates of birth, phone numbers, bank account numbers, financial transactions and profile data; the company said it has no confirmed evidence of compromise and has escalated the matter to its security team for investigation. The breach follows a separate incident in which an AI music service had source code and user data exposed, including tens of millions of email addresses, phone numbers and partial payment card details, highlighting a broader trend of credential and financial data exposure across online platforms.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In March 2026, threat actors claimed to have targeted Paidwork, a gig‑work platform where users complete small jobs for pay. The alleged intrusion remained unverified until mid‑July 2026, when a threat actor released an 11‑gigabyte database said to have been stolen from Paidwork. The actor asserted that the database contained information for roughly 22 million users. Have I Been Pwned (HIBP) obtained the leaked file and published its analysis on Monday, July 20 2026, the same day the SecurityWeek article was published. SecurityWeek had reached out to both Suno and Paidwork for comment prior to publishing the piece. The same SecurityWeek article also reported on a separate data breach affecting the AI music generator Suno, which had exposed source code and user data earlier in November 2025.

Cyber Incident Image

HIBP’s analysis identified 23.3 million unique email addresses within the leaked data. The exposed information also included users’ names, password hashes, physical addresses, dates of birth, and phone numbers. Financial details such as bank account numbers and transaction records were present in the dataset. Additionally, user profile information describing individuals’ activity on the platform was part of the leak. The service noted that the volume and variety of data matched the scale claimed by the attacker.

Paidwork responded to the HIBP report by issuing a statement to SecurityWeek, saying it was aware of the claim but had no confirmed evidence that its systems or user accounts had been compromised. The company emphasized that it takes such reports seriously and has already escalated the matter to its internal security team for investigation. No further details about the investigation’s progress, potential containment steps, or a timeline for resolution were disclosed in the available sources.

Sources
Sources available to members
1 source