logo

PayPal Flaw Exposed Email Addresses, Social Security Numbers for 6 Months

ID: bcca4071-ad51-5952-96c9-21130afd2dca

STIX ID: report--bcca4071-ad51-5952-96c9-21130afd2dca

Feed Name: TechRepublic Security

Threat Score
55/100

Date Published: 2026-02-21

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

PayPal disclosed that a code modification in its PayPal Working Capital loan platform inadvertently exposed sensitive PII — including names, emails, phone numbers, business addresses, dates of birth, and Social Security numbers — for roughly 100 customers between July 1 and December 13, 2025; PayPal detected unauthorized access, refunded a small number of fraudulent transactions, rolled back the faulty code, reset affected account passwords, and offered two years of credit monitoring and identity restoration services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.