PayPal Data Breach: Customer Information Exposed, Passwords Reset, Unauthorized Transactions Confirmed
PayPal Data Breach Exposes Sensitive Customer Information
A recent data breach at PayPal has exposed sensitive customer information, including Social Security numbers and dates of birth, for over five months.
Breach Details
The incident, which affected approximately 100 customers, was linked to the PayPal Working Capital loan application system. The breach occurred between July 1, 2025, and December 12, 2025, when an attacker exploited an error in the system to gain unauthorized access to customer data.
Exposed Data and Consequences
The exposed data includes full names, addresses, phone numbers, business addresses, Social Security numbers, and dates of birth. The breach has resulted in unauthorized transactions on some accounts, with PayPal issuing refunds to affected customers. However, the company has not publicly disclosed the amounts involved or the methods used by the attacker.
Response and Precautions
In response to the breach, PayPal has reset passwords for impacted accounts and offered two years of complimentary credit monitoring and identity restoration services to affected customers. The company has also advised all users to review their account activity and transaction history for suspicious behavior.
Questions and Concerns
The incident also raises questions about the cause of the breach, with PayPal describing it as an “error” within the loan application system. Further clarification on this matter is still awaited.
