Data leak

PayPal App Coding Error Data Breach and Fraud

πŸ“… 2026-02-23
Primary Source β†—

Incident Details

PayPal disclosed a data breach and associated fraud incident caused by a coding error in its payment application. The error allowed unauthorized access to a subset of user account data and was used to facilitate fraud against affected customers. PayPal detected the issue and remediated the coding error. Affected customers were notified and offered remediation. The incident is notable as a software-error-driven breach rather than a traditional hack β€” an increasingly recognized breach category as complex application ecosystems create more opportunities for implementation flaws to expose user data.

Technical Details

Initial Attack Vector
A coding error in PayPal's application enabled unauthorized data access and facilitated fraud against a subset of PayPal users; the error was in the app's data handling logic rather than a direct attack by external threat actors

Timeline

  1. 2026-02-23 Breach occurred
  2. 2026-02-23 Publicly disclosed