Cyber Security News

PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months

PayPal has issued a formal data breach notification disclosing that a coding error in its PayPal Working Capital (PPWC) loan application exposed the personally identifiable information (PII) of an undisclosed number of customers for approximately six months, from July 1, 2025, to December 13, 2025.

The company detected the unauthorized exposure on December 12, 2025, and formally notified affected customers via written disclosure dated February 10, 2026, from its San Jose, California headquarters.

The breach resulted not from an external intrusion campaign but from an internal software defect, a code change within the PPWC loan application interface that inadvertently permitted unauthorized third parties to access customer PII.

PayPal confirmed that the responsible code change has since been rolled back and that unauthorized access to its systems has been terminated. The company also stated that no law enforcement investigation delayed the issuance of this notification.

PayPal Data Breach

The categories of personal information potentially exposed during the breach window are highly sensitive and include full name, email address, phone number, business address, Social Security number (SSN), and date of birth.

The combination of SSNs and date of birth alongside business contact details creates a high-risk profile for identity theft, financial fraud, and social engineering attacks targeting affected individuals.

PayPal noted that a small number of customers also experienced unauthorized transactions on their accounts, and the company has issued refunds to those individuals.

Following the discovery, PayPal initiated a full investigation, terminated unauthorized system access, and enforced mandatory password resets for all affected accounts. Enhanced security controls were implemented to require new credentials upon the next login.

As a remediation measure, the company is offering two years of complimentary three-bureau credit monitoring and identity restoration services through Equifax Complete™ Premier, which includes up to $1,000,000 in identity theft insurance coverage.

Affected users must enroll via Equifax using their provided activation code before the July 31, 2026, deadline.

Affected customers are urged to review their account transaction history, monitor their credit reports through annualcreditreport.com, and consider placing a fraud alert or credit freeze with all three major bureaus, Equifax, Experian, and TransUnion, at no cost.

PayPal also reminded users that the company will never request account credentials, passwords, or one-time authentication codes via call, text, or email.

A spokesperson for PayPal reached out to Cyber Security News stated that, “When there is a potential exposure of customer information, PayPal is obligated to notify the affected customers. In this situation, PayPal’s systems were not compromised. Therefore, we reached out to approximately 100 customers who were potentially impacted to raise awareness about this matter.”

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago