PayPal Data Breach – 6 Months of Users’ Data Leaked Online
PayPal has notified a limited number of customers about a cybersecurity incident involving the exposure of their personally identifiable information (PII) due to a software error in the PayPal Working Capital (PPWC) loan application. This exposure lasted…
PayPal has notified a limited number of customers about a cybersecurity incident involving the exposure of their personally identifiable information (PII) due to a software error in the PayPal Working Capital (PPWC) loan application. This exposure lasted from July 1, 2025, to December 13, 2025.
The exposure affected business contact details along with sensitive personal data. PayPal discovered the issue on December 12, 2025, and rectified the faulty code the next day. The compromised information included:
Name Email address Phone number Business address Social Security number (SSN) Date of birth
The issue originated from a mistake in the PPWC loan application process, a service providing small businesses with financing options based on their PayPal transaction history. PayPal confirmed that the notification was not delayed due to any law enforcement investigation.
The exposure affected business contact details along with sensitive personal data.
Terminated unauthorized access and corrected the problematic code. Reset passwords for affected accounts, requiring users to create a new password upon their next login. Issued refunds to customers impacted by unauthorized transactions. Implemented enhanced security measures.
Additionally, PayPal is offering two years of complimentary credit monitoring and identity restoration services through Equifax. Affected customers must enroll by June 30, 2026.
Recommended Actions for Affected Customers
Review account statements and transaction history for suspicious activity. Enroll in the free Equifax monitoring services, as detailed in the notification letter. Be vigilant against phishing attempts. Note that PayPal will not request passwords or authentication factors via email, phone, or text. Follow best practices: use unique passwords, enable multi-factor authentication, and avoid clicking on suspicious links.
PayPal described the number of affected customers as "small." This incident is not connected to previous breaches, such as the 2022 credential-stuffing attack. Due to the prolonged exposure of SSNs and dates of birth, the credit monitoring offer is crucial to mitigate the risk of identity theft and fraud.
Customers who received the notification should act promptly. For further information, visit PayPal’s Help & Contact section or the Equifax enrollment page mentioned in the letter. PayPal has not issued a public press release beyond customer notifications and has not responded to requests for additional comment.
Based on reporting by GBHackers.
