Article

Data on 23m users of money-making app Paidwork leaked online

by TechDefused Newsroom
A person wearing a hoodie stands against a backdrop of green binary code, with their face illuminated by the projected numbers. The image evokes themes of technology and digital transformation. — Credit: Photo by Joshua Koblin / Unsplash cPhoto by Joshua Koblin / Unsplash
Photo by Joshua Koblin / Unsplash

Personal and financial data belonging to more than 23 million users of Paidwork, an app that pays people small sums to play games, watch adverts and fill in surveys, has been leaked online.

The dataset was added at the weekend to Have I Been Pwned, the widely used breach notification service run by security researcher Troy Hunt, after being publicly released this month.

Hackers claimed to have stolen the data in March, and it was first advertised for sale in April by a seller using the handle "HACKFORMETOME".

The listing puts the leak at 23.27 million user records, contained in an archive of almost 11GB.

The exposed information is unusually extensive.

Alongside email addresses and passwords, the records are said to include bank account numbers, payout histories, phone numbers, physical addresses, dates of birth, profile photographs, IP addresses, device information, financial transaction records and even education levels.

The passwords were stored as bcrypt hashes, a form of scrambling that makes them difficult, though not impossible, to crack.

The financial details are a particular concern because of how Paidwork operates.

The platform requires users to accumulate a $10 minimum balance before they can cash out, meaning millions of people handed over banking or payment details in the expectation of eventually being paid.

That combination of banking information, home addresses and transaction histories in a single leak sets this breach apart from the more routine spills of emails and passwords.

Criminals could use it for identity theft, financial fraud or highly convincing scam messages that reference real payment details to appear legitimate.

Paidwork had not publicly acknowledged the alleged breach at the time of publication.

The company did not immediately respond to requests for confirmation, or to questions about whether affected users would be notified.

The incident echoes earlier breaches in the gig economy, including the 2016 Uber hack affecting 57 million people and the 2019 DoorDash breach, though few have combined full banking details with such a broad range of personal information.

Anyone who has used Paidwork should assume their details may be in the leak.

The most urgent step is to change the Paidwork password anywhere else it has been reused, since attackers routinely test leaked credentials against email, banking and shopping accounts.

Users should also monitor bank statements for unfamiliar transactions and treat unexpected emails, texts or calls with suspicion, particularly any that mention Paidwork, quote personal details or ask for payment information.

Turning on two-factor authentication, which requires a second code to log in, adds a further layer of protection on accounts that support it.

People can check whether their email address appears in the leak for free at haveibeenpwned.com.

by TechDefused Newsroom