PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months
PayPal has announced a data breach related to its PayPal Working Capital (PPWC) loan application, caused by a coding error that exposed personally identifiable information (PII) of customers from July 1, 2025, to December 13, 2025.
PayPal has announced a data breach related to its PayPal Working Capital (PPWC) loan application, caused by a coding error that exposed personally identifiable information (PII) of customers from July 1, 2025, to December 13, 2025.
The company identified the exposure on December 12, 2025, and communicated the issue to affected customers in a written notice dated February 10, 2026, from its San Jose, California headquarters.
The breach was due to an internal software defect in the PPWC loan application interface, allowing unauthorized third parties to access customer PII. The responsible code change has been reversed, and unauthorized access has been terminated. No law enforcement investigation delayed this notification.
Data Compromised and Scope of Exposure
The breach potentially exposed sensitive personal information, including:
Full name Email address Phone number Business address Social Security number (SSN) Date of birth
The breach was due to an internal software defect in the PPWC loan application interface, allowing unauthorized third parties to access customer PII.
This combination of data creates a high-risk profile for identity theft, financial fraud, and social engineering attacks.
Some customers experienced unauthorized transactions, and PayPal has issued refunds. Following the breach, PayPal conducted a full investigation, ended unauthorized access, and mandated password resets for affected accounts. Enhanced security measures now require new credentials upon login.
PayPal is offering affected customers two years of free three-bureau credit monitoring and identity restoration services through Equifax Complete™ Premier, including up to $1,000,000 in identity theft insurance. Enrollment is required by July 31, 2026.
Affected customers are advised to review account transactions, monitor credit reports via annualcreditreport.com , and consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion.
PayPal reminds users that it will never request account credentials, passwords, or authentication codes via call, text, or email.
Based on reporting by Cyber Security News.
