Threat Intelligence Brief
Curated summary with source attribution
Source: helpnetsecurity.com
Threat Risk: High
Victim: Paidwork users
Incident: A production database intrusion resulting in a massive data leak.
Impact: Exposure of PII, bank account numbers, and hashed passwords for 23 million users.
Attacker: Unidentified threat actor (alias ‘hackformetome’)
Analysis: An intrusion in March 2026 led to an 11GB data dump containing sensitive PII and financial details. While passwords were hashed with bcrypt, the exposure of bank account numbers and home addresses significantly increases the risk of identity theft and targeted phishing. The lack of official acknowledgment from the company leaves users in the dark regarding the full scope of the compromise.
Recommendations: Update passwords immediately on Paidwork and any accounts sharing the same credentials.; Enable multi-factor authentication (MFA) across all sensitive online accounts.; Monitor bank accounts and credit reports for unauthorized activity.
Source: Help Net Security
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source