Data Breaches

PayPal Data Breach Led to Fraudulent Transactions

PayPal blamed an application error for the exposure of customer personal information for nearly 6 months. 

PayPal data breach

PayPal recently disclosed a data breach that affected customers’ personal information and led to fraudulent transactions.

Notification letters sent to impacted individuals revealed that the cybersecurity incident was caused by an error in the PayPal Working Capital (PPWC) loan application.

Due to the error, the personal information of a “small number of customers” was exposed for nearly six months, between July 1 and December 13, 2025.

Exposed information included names, email addresses, dates of birth, phone numbers, and business addresses combined with SSNs. 

The code that had introduced the error was rolled back and the affected customers’ passwords were reset. However, the vulnerability was exploited before it was patched.

“A few customers experienced unauthorized transactions on their account and PayPal has issued refunds to these customers,” PayPal said in its notification, a copy of which was submitted to authorities in Massachusetts. 

Advertisement. Scroll to continue reading.

In a statement, PayPal said it notified the roughly 100 customers affected by the incident, but noted that its “systems were not compromised.” 

This contradicts the official notification to affected users, which states that it “terminated the unauthorized access to PayPal’s systems” after detecting the breach. 

SecurityWeek has reached out to PayPal for clarification.

Related: French Government Says 1.2 Million Bank Accounts Exposed in Breach

Related: PayPal Phishing Campaign Employs Genuine Links to Take Over Accounts

Related: Malicious NPM Packages Target Cryptocurrency, PayPal Users

Related Content

Data Breaches

The figure is far higher than the counts that surfaced in earlier filings and patient notifications.

Data Breaches

Southern Company is notifying customers that their utility account information was accessed by hackers.

Data Breaches

The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack.

Data Breaches

Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users.

Data Breaches

The Arizona Supreme Court said the information was copied for people dating back as far as 30 years.

Data Breaches

Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens.

Data Breaches

Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.

Data Breaches

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version