The PayPal data breach disclosed in February 2026 involved a software error in the PayPal Working Capital loan application that exposed personal information belonging to a small number of customers. The affected information included names, email addresses, phone numbers, business addresses, dates of birth, and Social Security numbers.
The incident is important because it was not simply a case of someone breaking through PayPal’s main security defenses. PayPal said the exposure resulted from an error in its Working Capital application, while unauthorized individuals were able to access exposed information. The company detected the issue on December 12, 2025, and rolled back the code change the following day.
There is also an important distinction between this incident and PayPal’s separate December 2022 cybersecurity event, which involved credential-stuffing attacks and affected approximately 35,000 accounts.
This guide explains what happened, what data was exposed, who was affected, whether money was stolen, what PayPal did in response, and what users should do to protect themselves.
What Happened in the PayPal Data Breach?
The 2026 PayPal data breach involved the PayPal Working Capital (PPWC) loan application used by business customers. A software error caused certain customers’ personally identifiable information to become accessible to unauthorized individuals between July 1 and December 13, 2025.
PayPal discovered the problem on December 12, 2025. The company then rolled back the code change responsible for the exposure, terminating the unauthorized access by December 13.
PayPal later notified affected customers about the incident. Reports based on the company’s notifications say approximately 100 customers were potentially affected. PayPal characterized this as a “small number of customers,” rather than a breach involving its entire customer base.
Was PayPal Actually Hacked?
Not in the conventional sense of a successful attack against PayPal’s core infrastructure. PayPal said its systems were not compromised and described the incident as a potential exposure caused by an application error. However, its customer notification stated that unauthorized individuals had access to the exposed information.
That distinction matters. A data exposure can happen because information is accidentally made accessible through a programming or configuration mistake, while a traditional cyberattack may involve an attacker exploiting a security vulnerability to penetrate a system.
For customers, however, the practical concern remains similar: sensitive personal information may have reached people who were not authorized to see it.
What Information Was Exposed?
The exposed information included several categories of personally identifiable information, including names, email addresses, phone numbers, business addresses, dates of birth, and Social Security numbers. The exact information associated with each affected person could vary.
The presence of Social Security numbers makes this incident more serious than a simple email-address leak. A combination of identifying information can potentially be used for phishing, impersonation, identity theft, or other forms of fraud.
The exposed information reportedly related to customers using PayPal Working Capital, meaning the incident was specifically connected with PayPal’s business-lending service rather than every PayPal account.
It is therefore inaccurate to describe the 2026 event as though all PayPal users had their personal information exposed. Available reporting indicates that the affected population was limited.
Was Credit Card or Bank Account Information Exposed?
Available reports about the 2026 incident specifically identify personal information such as names, contact details, dates of birth, business addresses, and Social Security numbers. They do not establish that PayPal exposed the payment-card or bank-account information of all PayPal users.
Users should still check their PayPal activity and financial accounts if they notice anything suspicious. PayPal advises customers to report unauthorized transactions through its Resolution Center.
Did the PayPal Data Breach Cause Unauthorized Transactions?
Yes, PayPal reported that a few customers experienced unauthorized transactions connected with the incident. The company said it issued refunds to customers affected by those transactions.
The exact number of customers who experienced unauthorized transactions has not been publicly specified in the available reporting.
This is an important point because a data exposure does not automatically mean that money was stolen from every affected account. The reported unauthorized transactions involved only a small subset of the customers affected by the information exposure.
If you use PayPal, regularly reviewing your transaction history is still a sensible precaution. Look for payments, transfers, or account changes you do not recognize and report suspicious activity promptly.
What Did PayPal Do After the Incident?
PayPal says it rolled back the code responsible for the exposure and terminated unauthorized access. It also reset passwords for affected accounts and implemented additional security measures.
Affected customers were also offered two years of complimentary credit monitoring and identity-restoration services through Equifax, according to breach notifications reported in February 2026.
The company also refunded unauthorized transactions associated with the incident where customers were affected.
PayPal maintains a Security Center where users can report fraud, suspicious messages, and unusual account activity and find security guidance.
Should Affected Customers Change Their Passwords?
Yes. If PayPal has notified you that your account was affected, follow the company’s instructions and create a new, unique password.
Even if you were not directly affected, using a unique password for PayPal is good security practice. Never reuse your PayPal password on email, social media, shopping sites, or other financial services.
PayPal also warns users about phishing attempts. The company says it will not ask for account passwords or one-time authentication codes through suspicious phone calls, texts, or emails.

PayPal Data Breach vs. the 2022 Security Incident
The 2026 PayPal data breach should not be confused with the major PayPal cybersecurity incident from December 2022. The two events had different causes, affected different information, and happened at different times.
In December 2022, attackers used credential stuffing to access approximately 35,000 PayPal accounts. Credential stuffing involves using usernames and passwords obtained elsewhere and automatically testing them against another service.
New York’s Department of Financial Services later found that PayPal had security deficiencies surrounding changes made to its systems for Form 1099-K tax documents. Those documents exposed sensitive information, including Social Security numbers and other identifying details.
In January 2025, New York’s DFS announced a $2 million penalty against PayPal over cybersecurity violations associated with the 2022 incident.
PayPal subsequently introduced additional protections, including CAPTCHA, rate limiting, password resets for affected accounts, and mandatory multifactor authentication for U.S. accounts as part of its response to the earlier event.
| Incident | Main Cause | Key Information |
|---|---|---|
| 2022 event | Credential stuffing and security-control failures | SSNs, names, addresses, tax IDs, dates of birth |
| 2026 disclosure | Software error in PayPal Working Capital application | Names, contact details, addresses, DOBs, SSNs |
This distinction prevents an important SEO and factual mistake: the 2026 incident was not the same breach as the 2022 PayPal credential-stuffing event.
What Should PayPal Users Do Now?
If PayPal has contacted you about the breach, follow its instructions immediately. If you have not received a notification, there is no evidence from the available reports that every PayPal customer was affected, but basic account-security precautions are still worthwhile.
Start with these steps:
- Check your PayPal account activity. Look for payments or transfers you do not recognize.
- Change your password if PayPal tells you that your account was affected.
- Use a unique password. Do not reuse it on other websites.
- Enable multifactor authentication if available for your account.
- Monitor your credit reports if sensitive identity information may have been exposed.
- Watch for phishing emails and texts. Criminals can use leaked personal details to make scams appear legitimate.
- Do not share authentication codes. Never give a one-time code to someone who contacts you unexpectedly.
- Report unauthorized transactions to PayPal quickly. PayPal directs users to its Resolution Center for payment disputes.
The most important lesson is that a breach notification can create a second wave of risk. Scammers may impersonate PayPal, banks, credit-monitoring companies, or government agencies and claim they are helping victims.
Never click a suspicious link simply because an email mentions a real PayPal breach.
How to Recognize a PayPal Phishing Scam
A PayPal-related phishing message may claim that your account was breached, locked, charged, or selected for an urgent security check. The goal is usually to make you reveal your password, verification code, payment information, or other sensitive details.
PayPal’s Security Center specifically provides guidance for suspicious emails and text messages and encourages users to report fraudulent activity.
Be particularly cautious when a message:
- Creates an extreme sense of urgency.
- Asks for your password or one-time code.
- Requests payment to “secure” your account.
- Tells you to install unfamiliar software.
- Uses a suspicious website address.
- Claims you must call an unfamiliar number immediately.
Instead of clicking the message’s link, open PayPal through your normal browser or official app and check your account directly.
Is PayPal Safe to Use After the Breach?
PayPal remains a major digital-payments platform, but no large online financial service can guarantee that security incidents will never happen. The 2026 incident demonstrates why both companies and customers need multiple layers of protection.
PayPal’s own annual filing acknowledges that it faces cybersecurity risks from human error, system errors, vulnerabilities, deception, insider threats, and other sources.
For users, security therefore should not depend entirely on the company. A unique password, multifactor authentication, careful phishing detection, and regular transaction monitoring can significantly reduce the consequences of an account compromise.
The 2026 incident also illustrates an important cybersecurity principle: a breach does not always begin with an attacker breaking through a firewall. Software mistakes, incorrect access controls, and application-development errors can expose sensitive information too.
What Does the PayPal Breach Mean for Consumers?
For most PayPal customers, the 2026 incident does not mean their accounts were automatically compromised. The available information indicates that the incident was limited to a small number of customers associated with PayPal Working Capital.
For people who were affected, however, the exposure of Social Security numbers and other identifying information deserves long-term attention.
Identity-related information can remain useful to criminals long after an incident has been fixed. That makes credit monitoring and awareness of suspicious communications particularly important for affected individuals.
The bigger takeaway is equally relevant to businesses: sensitive information should have strict access controls, application changes should undergo proper security review, and authentication protections should be implemented before—not after—a security incident.
Frequently Asked Questions
Was PayPal breached in 2026?
PayPal disclosed a 2025 security incident involving its PayPal Working Capital application in February 2026. The company attributed the exposure to a software error and said a small number of customers were affected.
When did the PayPal data breach happen?
The affected information was exposed from July 1 through December 13, 2025. PayPal detected the issue on December 12 and rolled back the problematic code the following day.
How many people were affected by the PayPal breach?
PayPal described the number as a small number of customers and told cybersecurity media that approximately 100 customers were potentially affected.
What information did the PayPal breach expose?
Reported exposed information included names, email addresses, phone numbers, business addresses, dates of birth, and Social Security numbers.
Did hackers steal money from PayPal customers?
PayPal reported that a few customers experienced unauthorized transactions associated with the incident and said it refunded those customers. The company has not publicly specified the exact number.
Should I change my PayPal password?
If PayPal notified you that your account was affected, follow its password-reset instructions. Regardless of the breach, using a unique password and multifactor authentication provides additional protection.
Was the 2026 PayPal breach the same as the 2022 breach?
No. The 2022 incident involved credential-stuffing attacks against approximately 35,000 accounts, while the 2026 disclosure concerned a software error in the PayPal Working Capital application.
Did PayPal offer credit monitoring to affected customers?
Yes. Reports based on PayPal’s breach notifications say affected customers were offered two years of free three-bureau credit monitoring and identity-restoration services through Equifax.
How can I report suspicious PayPal activity?
PayPal directs users to report fraud and unusual account activity through its Security Center and unauthorized payments through its Resolution Center.
Is PayPal safe to use now?
The existence of a security incident does not mean every PayPal account is unsafe. Users should maintain unique credentials, enable available security protections, monitor transactions, and remain alert for phishing attempts. PayPal continues to provide security and fraud-reporting resources through its Security Center.
