{"id":10842,"date":"2026-02-21T10:03:50","date_gmt":"2026-02-21T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/21\/paypal-data-breach-exposes-ssns-and-business-pii-of-customers-for-over-six-months\/"},"modified":"2026-02-21T10:03:50","modified_gmt":"2026-02-21T10:03:50","slug":"paypal-data-breach-exposes-ssns-and-business-pii-of-customers-for-over-six-months","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/21\/paypal-data-breach-exposes-ssns-and-business-pii-of-customers-for-over-six-months\/","title":{"rendered":"PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months"},"content":{"rendered":"<p>    PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>PayPal has issued a formal data breach notification disclosing that a coding error in its PayPal Working Capital (PPWC) loan application exposed the personally identifiable information (PII) of an undisclosed number of customers for approximately six months, from July 1, 2025, to December 13, 2025.<\/p>\n<p>The company detected the unauthorized exposure on December 12, 2025, and formally notified affected customers via written disclosure dated February 10, 2026, from its San Jose, California headquarters.<\/p>\n<p>The breach resulted not from an external intrusion campaign but from an internal software defect, a code change within the PPWC loan application interface that inadvertently permitted unauthorized third parties to access customer PII.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/paypal-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">PayPal confirmed that the responsible code<\/a> change has since been rolled back and that unauthorized access to its systems has been terminated. The company also stated that no law enforcement investigation delayed the issuance of this notification.<\/p>\n<h2 class=\"wp-block-heading\" id=\"data-compromised-and-scope-of-exposure\"><strong>PayPal Data Breach<\/strong><\/h2>\n<p>The categories of personal information potentially exposed during the breach window are highly sensitive and include full name, email address, phone number, business address, Social Security number (SSN), and date of birth.<\/p>\n<p>The combination of SSNs and date of birth alongside business contact details creates a high-risk profile for identity theft, financial fraud, and social engineering attacks targeting affected individuals.<\/p>\n<p><a href=\"https:\/\/s3.documentcloud.org\/documents\/27345193\/paypal-february-2026-breach-notification.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PayPal noted that a small number of customers also experienced<\/a> unauthorized transactions on their accounts, and the company has issued refunds to those individuals.<\/p>\n<p>Following the discovery, PayPal initiated a full investigation, terminated unauthorized system access, and enforced mandatory password resets for all affected accounts. Enhanced security controls were implemented to require new credentials upon the next login.<\/p>\n<p>As a remediation measure, the company is offering two years of complimentary three-bureau credit monitoring and identity restoration services through Equifax Complete<img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/2122.png?ssl=1\" alt=\"\u2122\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> Premier, which includes up to $1,000,000 in identity theft insurance coverage.<\/p>\n<p>Affected users must enroll via Equifax using their provided activation code before the July 31, 2026, deadline.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">Affected customers are urged to review their account transaction history, monitor their credit reports through\u00a0<em>annualcreditreport.com<\/em>, and consider placing a fraud alert or credit freeze with all three major bureaus, Equifax, Experian, and TransUnion, at no cost.<\/span><\/p>\n<p>PayPal also reminded users that the company will never request account credentials, passwords, or one-time authentication codes via call, text, or email.<\/p>\n<p>A spokesperson for PayPal stated to Cybersecurity News that, \u201cWhen there is a potential exposure of customer information, PayPal is obligated to notify the affected customers. In this situation, PayPal\u2019s systems were not compromised. Therefore, we reached out to approximately 100 customers who were potentially impacted to raise awareness about this matter.\u201d<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/paypal-data-breach-expose-customer-data\/\">PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/paypal-data-breach-expose-customer-data\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months PayPal has issued a formal data breach notification disclosing that a coding error in its PayPal Working Capital (PPWC) loan application exposed the personally identifiable information (PII) of an undisclosed number of customers for approximately six months, from July 1, 2025, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-10842","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10842"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10842"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10842\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}