Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

PayPal Data Breach Led to Fraudulent Transactions

PayPal blamed an application error for the exposure of customer personal information for nearly 6 months. 

PayPal data breach

PayPal recently disclosed a data breach that affected customers’ personal information and led to fraudulent transactions.

Notification letters sent to impacted individuals revealed that the cybersecurity incident was caused by an error in the PayPal Working Capital (PPWC) loan application.

Due to the error, the personal information of a “small number of customers” was exposed for nearly six months, between July 1 and December 13, 2025.

Exposed information included names, email addresses, dates of birth, phone numbers, and business addresses combined with SSNs. 

The code that had introduced the error was rolled back and the affected customers’ passwords were reset. However, the vulnerability was exploited before it was patched.

“A few customers experienced unauthorized transactions on their account and PayPal has issued refunds to these customers,” PayPal said in its notification, a copy of which was submitted to authorities in Massachusetts. 

Advertisement. Scroll to continue reading.

In a statement, PayPal said it notified the roughly 100 customers affected by the incident, but noted that its “systems were not compromised.” 

This contradicts the official notification to affected users, which states that it “terminated the unauthorized access to PayPal’s systems” after detecting the breach. 

SecurityWeek has reached out to PayPal for clarification.

Related: French Government Says 1.2 Million Bank Accounts Exposed in Breach

Related: PayPal Phishing Campaign Employs Genuine Links to Take Over Accounts

Related: Malicious NPM Packages Target Cryptocurrency, PayPal Users

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.