Paidwork Gig Platform Breach Leaks 23.3 M Accounts, Banking Details and Password Hashes
What Happened – In March 2026 attackers claimed to have exfiltrated data from the gig‑economy marketplace Paidwork. Over 11 GB of data containing more than 23 million unique email addresses, banking numbers, payout histories and bcrypt‑hashed passwords was posted publicly in July 2026.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a failure to enforce strong access‑control policies (password complexity, MFA, credential rotation) that SOC 2 CC6.1‑CC6.3 require.
- Continuous evidence of credential‑management controls (e.g., MFA adoption rates, password‑policy enforcement logs) is essential to demonstrate due‑diligence during a SOC 2 audit.
- The breach underscores the need for security‑awareness training that reinforces safe credential handling and prompt reporting of suspicious activity.
Who Is Affected – Gig‑economy platforms, freelance marketplaces, and any SaaS provider that stores user‑generated financial and personal data.
Recommended Actions –
- Map the incident to SOC 2 CC6.1 (Logical Access Controls) and CC6.2 (User Access Provisioning) and collect audit evidence of password‑policy enforcement and MFA coverage.
- Conduct an immediate credential‑reset for all affected accounts and enforce MFA where possible.
- Review and tighten password‑storage practices; verify bcrypt parameters meet current best‑practice work factors.
- Update security‑awareness training to include credential‑theft detection and reporting.
Source: Have I Been Pwned – Paidwork Breach
Technical Notes – The leak includes email addresses, names, dates of birth, phone numbers, physical addresses, device IDs, IP addresses, education levels, gender, profile photos, banking account numbers, payout histories and bcrypt‑hashed passwords. No specific CVE or exploit was disclosed; the breach appears to stem from credential compromise or insufficient access controls. Source: same as above