Data Security, Breach

PayPal data breach exposes sensitive user information

A PayPal logo is seen outside the company's headquarters

Security Affairs reports that PayPal experienced a significant data breach affecting a small number of customers due to a software error in its PayPal Working Capital loan application. The vulnerability exposed sensitive personal information between July 1 and December 13, 2025, before being identified and rectified.

The breach, stemming from a coding error, led to the exposure of customer business contact details, including names, emails, phone numbers, and addresses. More critically, Social Security numbers and dates of birth were also compromised. PayPal discovered the issue on December 12, 2025, and has since rolled back the faulty code. The company stated the notification was not delayed due to any law enforcement investigation, and it has implemented stronger security checks and reset affected passwords.

A small number of users reported unauthorized transactions, which have been refunded. Affected individuals are being offered two years of complimentary credit monitoring and identity restoration services through Equifax.

Source: Security Affairs

You can skip this ad in 5 seconds