Data leak
PayPal Working Capital Loan Application Data Exposure - Code Error
Primary Source βIncident Details
A code update error in PayPal’s Working Capital loan application exposed approximately 100 customers’ personally identifiable information from July 1 to December 13, 2025 β approximately six months. PayPal discovered the issue on December 12, rolled back the code on December 13, 2025, and sent breach notifications on February 10, 2026. Exposed data included business contact information (name, email, phone, address), Social Security numbers, and dates of birth. A small number of customers experienced unauthorized transactions on their accounts and received refunds. PayPal reset affected account passwords, implemented enhanced security controls, and offered two years of complimentary three-bureau credit monitoring via Equifax.
Technical Details
- Initial Attack Vector
- Routine code update to the PayPal Working Capital (PPWC) loan application contained a programming error that left customer PII accessible without authorization for approximately six months
- Vendor / Product
- PayPal Working Capital (PPWC loan application)
Timeline
- 2025-07-01 Breach occurred
- 2026-02-10 Publicly disclosed
- 2026-02-10 Customers notified