Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - PayPal Customer Data Exposed for Six Months in Breach
Data Breach Attacks Data Loss Prevention Data Protection Latest News News & Analysis

PayPal Customer Data Exposed for Six Months in Breach

Kirsten DoyleBy Kirsten DoyleFebruary 24, 20264 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
PayPal Customer Data Exposed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

PayPal has disclosed a data breach that exposed some of its customers’ personal information and led to fraudulent transactions. 

The company said it happed due to an error in its PayPal Working Capital (“PPWC”) loan application, an offering that gives businesses a cash advance based on their PayPal sales history. 

Between 1 July and 13 December 2025, the PII of a small number of customers was exposed to bad actors. PayPal added that it has since rolled back the code change responsible for this error. 

Types of data exposed include, full names, email addresses, phone numbers, mailing addresses, dates of birth, and SSNs. PayPal insisted that no financial account information, login credentials, passwords, and credit card or bank account numbers were accessed or exposed.  

“Upon learning about this unauthorized activity, we began an investigation and terminated the unauthorized access to PayPal’s systems. We reset the passwords of the affected PayPal accounts and implemented enhanced security controls that will require you to establish a new password the next time you log in to your account if you have not already done so. A few customers experienced unauthorized transactions on their account and PayPal has issued refunds to these customers,” the company added. 

PayPal is in the process of notifying affected individuals and has taken steps to contain the incident and emphasized that it has implemented additional monitoring and security enhancements as part of its response.  

More Robust SDLC Needed  

Noelle Murata, Sr. Security Engineer at Xcape Inc, said: “PayPal’s Working Capital glitch serves as a prime example of how a subtle logic error can be as impactful as a high-profile hack, with customer data remaining exposed for nearly six months undetected. Although the exposure seems minor, the severity of the information led to fraudulent transactions and highlights the need for key industries to follow fundamental application security practices. 

She added that for financial platforms, security must encompass more than just transaction protection; it needs to extend to all associated products and processes handling customer data. “While improved monitoring is crucial, preventing such incidents necessitates more robust secure development lifecycle controls (SDLC). 

“Customers impacted should view this as an identity theft risk, not just a minor account problem. Enrol in the provided credit monitoring, secure credit files where possible, and exercise extreme caution with any “PayPal” communications referencing their business or loan history. Apparently, a six-month undetected coding error that leaks your Social Security Number is just a feature, not a bug.” 

Contradictory Messaging 

Denis Calderone CRO & COO at Suzu Labs, said: “PayPal told the media their ‘systems were not compromised,’ but the breach notification letter they filed with Massachusetts says they ‘terminated the unauthorized access to PayPal’s systems.’ Those two statements can’t both be true. Either someone accessed your systems without authorization, or they didn’t. It might be just a poorly worded press release, but words are important. You don’t get to tell regulators one thing and the press another.” 

According to him, this kind of contradictory messaging erodes the trust that breach notifications are supposed to rebuild. “When a company gets caught playing word games with incident disclosures, it makes you question what else is being minimized. Is the record count correct, and was the exposure really limited to the data types they listed? We can’t verify any of that independently, so we’re relying on the company’s transparency.” 

Calderone added that what they have disclosed is bad enough: SSNs, dates of birth, and names exposed for nearly six months before anyone noticed, with some customers hit by fraudulent transactions. “But the bigger issue here is accountability in disclosure. Say what happened. Say it consistently. And say it quickly.” 

Small Internal Failures 

Simon Pamplin, CTO of Certes, added that this latest incident highlights a recurring issue in cybersecurity: breaches are not always the result of sophisticated external attacks, but of small internal failures that expose highly sensitive data for extended periods of time. 

“What is particularly concerning here is the duration. Five months is a significant window in which personal and financial identifiers including Social Security numbers and dates of birth may have been accessible. Once that data is copied, the risk does not disappear when the bug is fixed or passwords are reset. It persists.” 

Pamplin stated that the immediate concern is fraud and phishing, which we are already seeing in the form of unauthorised transactions. “But the longer-term risk is often overlooked. Criminal groups increasingly operate on a harvest now, decrypt later model, quietly collecting encrypted or protected data today with the expectation that advances in computing power, including quantum capability, will allow them to unlock it in the future.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}