PayPal Working Capital data breach exposes sensitive customer information due to software error
PayPal Breach Exposed Data for 6 Months, Funds Stolen What Happened in the Breach PayPal confirmed that a software error in its PayPal Working Capital (PPWC) loan application led to a data exposure that lasted nearly…
Key points
- Data breach in PayPal Working Capital (PPWC) loan application.
- Caused by a software error, not an external hack.
- Exposure window: July 1, 2025, to December 12, 2025.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Dec 12, 2025
- Updated
- Jul 22, 2026
- Confidence
- Medium
- Evidence
- 3 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch internet-facing systems, credential abuse and exploit activity.
Business impact
- Impact area
- Confidentiality
- Likely asset
- User or customer data
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
PayPal Breach Exposed Data for 6 Months, Funds Stolen What Happened in the Breach PayPal confirmed that a software error in its PayPal Working Capital (PPWC) loan application led to a data exposure that lasted nearly six months . According to PayPal’s breach notice filed with Massachusetts authorities, the error in the PPWC application exposed personal data to unauthorized individuals between July 1 2025 and December 13 2025 . PayPal detected the issue on December 12 2025 and rolled back the faulty code the next day. The company emphasized that its core systems were not compromised and said only a small number of customers, around 100 , were potentially affected. Nevertheless, exposed data included names, email addresses, phone numbers, business addresses, Social Security numbers and dates of birth. PayPal found that some victims experienced unauthorized transactions , prompting the firm to refund affected accounts and reset passwords. The breach underscores how a single coding error can expose sensitive data even when the underlying infrastructure is secure. Timeline: From First Access To Latest Update July 1 2025: A change to the PPWC loan application inadvertently introduced a bug that exposed customer data. The exposure continued undetected for months. July 1 – December 13 2025: Personal information—names, contact details and Social Security numbers —remained accessible to unauthorized parties. December 12 2025: PayPal discovered unauthorized access during an internal investigation. It determined that the bug had been active for more than five months . December 13 2025: PayPal rolled back the problematic code, blocking further access to the exposed data. February 10 2026: The company sent breach-notification letters to affected customers. The letters explained what information was involved, described the remediation steps taken, and offered complimentary credit monitoring. February 20 2026: BleepingComputer reported on the incident, citing PayPal’s notifications and statements. On the same day The Register and other outlets confirmed that about 100 customers were notified. February 21 – 22 2026: Additional reports from TechRepublic, Cybernews and Techzine gave further details on the nature of the bug and the data exposed. PayPal reiterated that it had not delayed disclosure for law‑enforcement reasons and that the core system had not been breached. Latest confirmed update: As of February 22 2026 , no regulators have announced investigations or fines related to the PPWC incident. PayPal continues to offer two years of free credit monitoring and identity‑restoration services to the affected users. No arrests or lawsuits have been reported. The bug in the PPWC application exposed sensitive personally identifiable information (PII). PayPal’s breach notice states that the compromised data may have included each customer’s name, email address, phone number, business address, Social Security number and date of birth. Reports confirm that approximately 100 customers were affected, although the exact number has not been publicly disclosed. The exposure did not involve PayPal’s main payment platform or other systems; the firm insists that the broader infrastructure remained secure. However, because the data set included unique identifiers such as Social Security numbers and dates of birth, the risk of identity theft and fraudulent account activity is significant. A few customers experienced unauthorized transactions, which PayPal refunded. Who Was Responsible (Confirmed Vs Alleged) PayPal attributes the incident to an internal coding error rather than an external hack. The company says a software modification in the PPWC loan application inadvertently exposed data to unauthorized individuals. There is no evidence that threat actors breached PayPal’s core systems; instead, the vulnerability allowed unknown individuals to access data that was unintentionally exposed. Because the flaw resulted from a configuration error and not a deliberate intrusion, no specific attacker has been identified. Nevertheless, individuals who discovered the exposure were able to view and potentially misuse the data; some used it to carry out fraudulent transactions. Law‑enforcement agencies have not announced any arrests or identified suspects. The incident was rooted in business‑logic failure rather than a classic hack. PayPal’s PPWC platform serves small businesses seeking fast access to financing. A code change introduced on July 1 2025 inadvertently made certain fields in the application interface publicly accessible. This misconfiguration exposed PII to any party who interacted with the application, even though no authentication bypass or network intrusion occurred. As soon as PayPal detected the error on December 12 2025 , it reversed the faulty code and blocked further access the next day. Social Security Numbers Exposed in PayPal Working Capital Breach PayPal has begun notifying a limited number of business customers about a data breach tied to its PayPal Working Capital (PPWC) loan application. According to breach notification letters, a software error exposed sensitive personal information between July 1 and December 12, 2025. The issue was discovered on December 12, after which PayPal says it reversed the problematic code and blocked unauthorized access. The exposed data included names, email addresses, phone numbers, business addresses, Social Security numbers, and dates of birth. While PayPal stated that approximately 100 customers were affected, some experienced unauthorized transactions. The company has since reset impacted passwords, issued refunds where necessary, and is offering two years of complimentary credit monitoring through Equifax. Why It Matters: Although the number of affected users appears small, the type of data exposed, particularly Social Security numbers and dates of birth, creates long-term identity theft and fraud risks. The incident also adds to a series of security-related events involving PayPal in 2025, raising broader concerns about systemic vulnerabilities and detection timelines. Six-Month Exposure Window: The breach reportedly began on July 1, 2025, and continued until December 12, 2025, when PayPal says it identified and addressed the issue. A six-month window of exposure is significant as it provides an extended opportunity for unauthorized individuals to access, collect, or exploit sensitive data before containment measures are implemented. Confirmed Unauthorized Transactions and Account Resets: PayPal acknowledged that a small number of affected users experienced unauthorized transactions tied directly to the breach. The company stated that it refunded impacted customers and reset passwords on affected accounts, requiring users to establish new credentials to regain access.
When was this signal reported?
Shadow Tier lists Dec 12, 2025 as the signal date.
Which organization is connected to this signal?
Paypal is the organization connected to this public signal.
Explore PaypalWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence