More than 23 million accounts from the gig-economy platform Paidwork were exposed, according to Have I Been Pwned. The incident dates to March 2026, and an approximately 11GB dataset was published openly in July 2026. It includes user profiles, banking details and worker payout histories, plus passwords — those at least as bcrypt hashes rather than plain text. Notably, Paidwork has not publicly acknowledged the incident. If you had an account there, change the password and keep an eye on the bank account involved.
After a breach: the part most people skip
A leaked email and phone number don't just sit in one dump — data brokers buy breach data, merge it with public records, and resell it. That's why the spam calls and phishing texts keep coming months later. Deleting your data from the breached company is only the first step; getting it out of the broker network is what actually stops the follow-on damage.