PayPal disclosed that a coding error in its PayPal Working Capital (PPWC) loan application exposed a small number of customers’ personally identifiable information (PII) to unauthorized parties for roughly six months (July 1 to December 13, 2025). The exposed data included business contact details (name, email, phone number, business address) and highly sensitive identifiers such as Social Security numbers and dates of birth; PayPal said its core systems were not compromised and that the issue stemmed from an internal software defect that was later rolled back.
PayPal detected the exposure on December 12, 2025, initiated an investigation, blocked the unauthorized access, and required password resets/new credentials for impacted accounts. A small number of affected customers reported unauthorized transactions, which PayPal said were refunded; reporting indicates approximately 100 customers were notified. PayPal also stated the notification was not delayed by law enforcement and is offering impacted individuals two years of credit monitoring/identity restoration services (via Equifax, per reporting) alongside strengthened security checks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
As part of its remediation, PayPal offered affected customers two years of credit monitoring and identity restoration services through Equifax. Enrollment for the service was made available following the February 2026 notification.
PayPal issued written breach notifications from its San Jose headquarters to impacted customers, disclosing the six-month exposure and available remediation. The notices said a small number of customers had unauthorized transactions, which PayPal refunded.
PayPal rolled back the code change in the PPWC interface, terminated unauthorized access, reset affected passwords, and added stronger login/security controls. The company said the exposure ended by December 13, 2025.
PayPal discovered the unauthorized activity and identified the underlying application error affecting PPWC customer data. The company said the issue was detected on December 12, 2025.
A coding error in PayPal's PayPal Working Capital loan application began exposing customer personal and business information, including Social Security numbers and dates of birth, to unauthorized access. The exposure window started on July 1, 2025 and ultimately affected about 100 customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourceteiss.co.uk
Open sourcethecyberthrone.in
Open sourcetechrepublic.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.