Site navigation

PayPal Data Breach: Customer Data Exposed for Six Months

Graham Turner

,

PayPal data breach
PayPal has confirmed that a security incident linked to its PayPal Working Capital loan application exposed personal data for up to six months.

Some PayPal users have begun receiving emails from the company confirming a data breach that exposed personal information to a threat actor who gained access to PayPal’s systems, with some customers reporting unauthorised transactions and being required to reset their passwords.

A breach notification letter, confirmed by Forbes Senior Contributor Davey Winder, states that a hacker gained access to PayPal systems on 1 July 2025. The attacker reportedly maintained access until 12 December 2025, when PayPal discovered the incident. Notifications dated 10 February indicate that some users were impacted “due to an error in its PayPal Working Capital (“PPWC”) loan application.”

It remains unclear how the attacker’s access developed. The situation is ongoing, and PayPal has provided limited technical detail beyond attributing the issue to a “code change.”

However a statement from a PayPal spokesperson said: “When there is a potential exposure of customer information, PayPal is required to notify affected customers. In this case, PayPal’s systems were not compromised. As such, we contacted the approximately 100 customers who were potentially impacted to provide awareness on this matter.”

That statement appears to contrast with language in the breach notification, which said that after an investigation the company had “terminated the unauthorized access to PayPal’s systems.”

In its notification to affected users, PayPal said: “Upon learning about this unauthorized activity, we promptly began an investigation and took action to address this incident, including by taking steps to prevent unauthorized actors from obtaining further personal information.”

The breach notification confirms that unauthorised access persisted for approximately six months before being identified. While the number of potentially affected accounts is understood to be limited, the duration of the exposure has raised questions about detection timelines and internal monitoring processes.

According to the notifications, the information potentially accessed includes names, email addresses, phone numbers, business addresses, Social Security numbers and dates of birth.

PayPal has also confirmed that “a few customers experienced unauthorized transactions on their account,” with the spokesperson stating that around 100 individuals were affected. Refunds have already been issued to those customers.

Alerts sent on 10 February reiterated that the vulnerability affected specific customers “due to an error in its PayPal Working Capital (PPWC) loan application.”


Recommended reading


The company has confirmed that it blocked the intruder’s access and reset the passwords of affected users, who should have been notified via email. Customers may be prompted to create new login credentials when accessing their accounts.

To mitigate potential risks, PayPal is offering two years of free credit monitoring and identity restoration services through Equifax. Users concerned about identity theft may also consider placing fraud alerts or credit freezes with credit reference agencies.

Commenting on the story, Keven Knight, CEO of Talion, said: “What is most concerning about this breach is that an organisation as large and reputable as PayPal, which holds highly sensitive data on its customers, has waited two months to notify individuals about this incident.
“While credit monitoring has been offered, victims were left in the dark, while the actor behind the incident was able to access their financial and personal data and conduct fraudulent transactions.
“PayPal has said it has refunded customers for the fraudulent transactions and updated the passwords on impacted accounts, but the attacker still has access to information that can’t be easily changed, which can still be of value to them in phishing scams and to sell to initial access brokers.
“PayPal has claimed its systems were not breached.
“This could imply the incident relates to a misconfigured system, which was then exploited maliciously. If this is the case, it’s a worrying security error. More worrying still is the fact it went unnoticed for six month.
“Customers would, and should, expect better.”

Join the Conversation at ITSX Summit

How is customer service and IT support evolving in the age of AI, automation, and digital transformation?

Join us at the ITSX Summit in Edinburgh on 5th March, to unpack the future of ITSM, ESM, Self Service, and User Experience.

The event will bring together senior leaders from IT, Service Management, and UX, providing an ideal forum for shared learning, collaboration, and high-level networking.

Register now to secure your free place at ITSX Summit.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data