HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Paidwork Gig Platform Breach Leaks 23.3 M Accounts, Banking Details and Password Hashes

Hackers claimed to have stolen more than 23 million user records from Paidwork, a gig‑economy marketplace, including banking information and bcrypt‑hashed passwords. The breach highlights gaps in access‑control enforcement that SOC 2 audits specifically evaluate.

LiveThreat™ Intelligence · 📅 July 20, 2026· 📰 haveibeenpwned.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
haveibeenpwned.com

Paidwork Gig Platform Breach Leaks 23.3 M Accounts, Banking Details and Password Hashes

What Happened – In March 2026 attackers claimed to have exfiltrated data from the gig‑economy marketplace Paidwork. Over 11 GB of data containing more than 23 million unique email addresses, banking numbers, payout histories and bcrypt‑hashed passwords was posted publicly in July 2026.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a failure to enforce strong access‑control policies (password complexity, MFA, credential rotation) that SOC 2 CC6.1‑CC6.3 require.
  • Continuous evidence of credential‑management controls (e.g., MFA adoption rates, password‑policy enforcement logs) is essential to demonstrate due‑diligence during a SOC 2 audit.
  • The breach underscores the need for security‑awareness training that reinforces safe credential handling and prompt reporting of suspicious activity.

Who Is Affected – Gig‑economy platforms, freelance marketplaces, and any SaaS provider that stores user‑generated financial and personal data.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Logical Access Controls) and CC6.2 (User Access Provisioning) and collect audit evidence of password‑policy enforcement and MFA coverage.
  • Conduct an immediate credential‑reset for all affected accounts and enforce MFA where possible.
  • Review and tighten password‑storage practices; verify bcrypt parameters meet current best‑practice work factors.
  • Update security‑awareness training to include credential‑theft detection and reporting.

Source: Have I Been Pwned – Paidwork Breach

Technical Notes – The leak includes email addresses, names, dates of birth, phone numbers, physical addresses, device IDs, IP addresses, education levels, gender, profile photos, banking account numbers, payout histories and bcrypt‑hashed passwords. No specific CVE or exploit was disclosed; the breach appears to stem from credential compromise or insufficient access controls. Source: same as above

📰 Original Source
https://haveibeenpwned.com/Breach/Paidwork

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →