Paidwork user database with 23 million records leaked online
A database containing bank account numbers, payout histories, and personal details for 23 million users of a gig economy platform is now publicly accessible.
Financial Data Exposed
Security researchers discovered a database dump containing records for 23 million users of Paidwork, a platform that connects workers with short-term digital tasks. The leaked data includes bank account numbers, payout transaction histories, email addresses, and personal identification details.
The database was added to Have I Been Pwned, a breach notification service, confirming the authenticity and scale of the exposure. Paidwork operates in multiple countries, meaning the breach affects users across different jurisdictions with varying data protection regulations.
Gig Economy Vulnerability
Platforms in the gig economy sector collect extensive financial data to process payments to workers, creating concentrated repositories of sensitive information. Unlike traditional employment relationships, gig workers often provide banking details to multiple platforms, multiplying their exposure when breaches occur.
The leaked payout histories could reveal income patterns and financial dependencies, information that extends beyond immediate fraud risk. Workers who relied on Paidwork as a primary income source may face targeted social engineering attempts based on their transaction patterns.
Response and Mitigation
Paidwork has not issued a public statement about the breach or provided guidance to affected users. Security experts recommend that anyone who used the platform monitor their bank accounts for unauthorized transactions and consider changing passwords on any services where they reused Paidwork credentials.
The exposure of bank account numbers does not immediately enable direct account access, but it provides information that can be used in combination with other leaked credentials or social engineering techniques to commit fraud.