PayPal Working Capital Bug Exposed Customer SSNs and PII for Six Months


PayPal disclosed a data exposure affecting approximately 100 customers of its Working Capital loan application. A software coding error from July 1 to December 13, 2025, made sensitive PII visible to unauthorized parties. The company found and fixed the issue on December 12, 2025, and sent notifications dated February 10, 2026, from San Jose, California.

No external hackers breached PayPal systems. A code change in the PPWC loan interface created the flaw. Third parties accessed data directly through the open interface. PayPal rolled back the code and blocked access within 24 hours of detection. No law enforcement investigation delayed disclosures.

Exposed information included full names, email addresses, phone numbers, business addresses, Social Security numbers, and dates of birth. This combination fuels identity theft and business fraud. A small number of accounts saw unauthorized transactions. PayPal issued full refunds to those victims.

The company reset passwords for all affected accounts. Users must create new credentials on next login. PayPal offers two years of free Equifax Complete Premier credit monitoring with $1M identity theft insurance. Enrollment deadline is July 31, 2026, using unique activation codes.

Spokesperson statement: “PayPal’s systems were not compromised. We reached out to approximately 100 customers who were potentially impacted.”

Exposed Data Categories

Data TypeSensitivityFraud Risk
Full NameHighIdentity theft
Email AddressHighPhishing target
Phone NumberHighSIM swap attacks
Business AddressMediumCorporate targeting
SSNCriticalFull identity theft
Date of BirthCriticalAccount takeover

SSN + DOB creates complete identity profiles.

Breach Timeline

  • July 1, 2025: Faulty code deployed in PPWC application.
  • Dec 12, 2025: PayPal detects exposure.
  • Dec 13, 2025: Code rollback blocks access.
  • Feb 10, 2026: Customer notifications sent.
  • Feb 20, 2026: Public disclosure.

Six-month exposure window confirmed.

Immediate Actions for Users

Follow these steps now:

  • Review PayPal transaction history for unauthorized activity.
  • Enroll in Equifax monitoring using activation code.
  • Check credit reports at annualcreditreport.com.
  • Place fraud alert with Equifax, Experian, TransUnion.
  • Consider credit freeze at all three bureaus (free).

Monitor for 12-24 months post-exposure.

PayPal Remediation Measures

Company implemented these fixes:

  • Rolled back problematic code change.
  • Reset passwords for all 100 affected accounts.
  • Issued refunds for unauthorized transactions.
  • Provided 2 years Equifax Complete Premier.
  • Enhanced PPWC application security controls.

No broader system compromise occurred.

Fraud Prevention Checklist

Protect against follow-on attacks:

  • Enable PayPal MFA if not active.
  • Update passwords on linked financial sites.
  • Watch for phishing claiming “breach response.”
  • Verify suspicious transactions immediately.
  • Report SSN misuse to FTC at IdentityTheft.gov.

PayPal never requests credentials via phone/text/email.

High-Risk Customer Profiles

Business owners face elevated threats:

  • Small business owners applying for PPWC loans.
  • Sole proprietors with personal SSNs on file.
  • Companies linking business/personal banking.

Synthetic identity fraud likely outcome.

Regulatory Context

PayPal history shows compliance scrutiny:

  • 2023: Credential stuffing hit 35,000 accounts.
  • 2025: $2M NY settlement for cybersecurity failures.

Current incident involves internal error, not intrusion.

Victim Support Resources

ServiceProviderDurationDeadline
3-Bureau Credit MonitoringEquifax2 yearsJuly 31, 2026
Identity Theft InsuranceEquifax$1MJuly 31, 2026
Credit ReportsAnnualCreditReport.comFree weeklyOngoing
Fraud Alerts3 Bureaus1 yearImmediate
Credit Freezes3 BureausIndefiniteImmediate

FAQ

How many PayPal customers were affected?

Approximately 100 customers.

What caused the six-month data exposure?

Coding error in PPWC loan application interface.

Was PayPal’s core platform hacked?

No. Internal software defect exposed data.

What PII was exposed in PayPal breach?

Names, emails, phones, addresses, SSNs, DOBs.

Does PayPal offer credit monitoring?

Yes, 2 years Equifax Complete Premier free.

Should I freeze my credit after PayPal exposure?

Yes, at Equifax, Experian, TransUnion immediately.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages