Paidwork, a microtask and gig economy platform, suffered a major data breach affecting 23,272,765 users after an intrusion in March 2026. The stolen database was later advertised for sale on a cybercrime forum under the alias "hackformetome", and by July nearly 11GB of the allegedly stolen data had been posted publicly. At the time of reporting, Paidwork had not publicly acknowledged the incident.
The exposed records reportedly include email addresses, names, contact details, home addresses, dates of birth, profile photos, device and IP data, worker payout histories, transaction records, bank account numbers, and passwords stored as bcrypt hashes. The breach appears to have exposed both user information and operational platform data, creating risks of account takeover, fraud, and follow-on phishing against affected users.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In July 2026, nearly 11GB of the allegedly stolen Paidwork data was publicly posted, including more than 23 million unique email addresses and other sensitive records.
In April 2026, the allegedly stolen Paidwork database was listed for sale or advertisement on a cybercrime forum under the alias “hackformetome,” signaling public criminal distribution of the data.
According to Have I Been Pwned and subsequent reporting, Paidwork suffered an intrusion in March 2026 that exposed extensive user, financial, and operational data affecting more than 23 million accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcecyberveille.ch
Open sourcehaveibeenpwned.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.