PayPal Data Breach – Customers Names, SSNs, and Dates of Birth Exposed

PayPal has disclosed a data breach affecting customers of its PayPal Working Capital (PPWC) loan application, where a software coding error left sensitive personally identifiable information (PII) exposed to unauthorized individuals for nearly six months.

The breach, identified on December 12, 2025, resulted in unauthorized access to customer data spanning from July 1, 2025, through December 13, 2025, a window of approximately 165 days.

The fintech giant issued formal breach notification letters to affected customers dated February 10, 2026, more than two months after discovering the incident.

PayPal stated that it rolled back the erroneous code change on December 13, 2025, one day after identifying the issue, effectively terminating unauthorized access. The company confirmed that no law enforcement investigation caused any delay in notifying affected users.

What Data Was Exposed

The compromised information includes a high-value combination of business contact and sensitive identity data.

Affected customers may have had their full name, email address, phone number, and business address exposed alongside their Social Security number (SSN) and date of birth details sufficient to enable identity theft, account takeover, and targeted social engineering attacks.

PayPal’s PPWC product is specifically designed for small businesses, providing quick access to merchant financing, meaning the breach disproportionately impacted business owners and sole proprietors who applied for working capital loans through the platform.

A small subset of affected customers also reported unauthorized transactions on their accounts as a direct result of the exposure, and PayPal confirmed it has issued refunds to those impacted while resetting passwords for all affected accounts.

Upon discovery, PayPal terminated unauthorized access, reset account passwords, and is now offering two years of complimentary three-bureau credit monitoring and identity restoration services through Equifax Complete Premier to all affected customers, with enrollment required by June 30, 2026.

The monitoring package includes daily Equifax credit report access, 3-bureau monitoring with email notifications, WebScan dark web alerts for SSN and financial account numbers, automatic fraud alerts, and up to $1,000,000 in identity theft insurance coverage. Affected users must enroll at Equifax using their provided unique activation code.

PayPal has yet to publicly disclose the exact number of customers affected by the breach. The company reminds users that it will never request account passwords, one-time codes, or authentication credentials via phone, text, or email, and users detecting any suspicious account activity should immediately change credentials and enable multi-factor authentication.

This incident follows PayPal’s January 2023 breach that compromised 35,000 accounts via credential stuffing and a $2 million settlement with the New York State Department of Financial Services in January 2025 for cybersecurity regulation violations.

A spokesperson for PayPal stated to Cyber Press that, “When there is a potential exposure of customer information, PayPal is obligated to notify the affected customers. In this situation, PayPal’s systems were not compromised. Therefore, we reached out to approximately 100 customers who were potentially impacted to raise awareness about this matter.”

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories