Data leak
PayPal App Coding Error Data Breach and Fraud
Primary Source βIncident Details
PayPal disclosed a data breach and associated fraud incident caused by a coding error in its payment
application. The error allowed unauthorized access to a subset of user account data and was used to facilitate
fraud against affected customers. PayPal detected the issue and remediated the coding error. Affected
customers were notified and offered remediation. The incident is notable as a software-error-driven breach
rather than a traditional hack β an increasingly recognized breach category as complex application ecosystems
create more opportunities for implementation flaws to expose user data.
Technical Details
- Initial Attack Vector
- A coding error in PayPal's application enabled unauthorized data access and facilitated fraud against a subset of PayPal users; the error was in the app's data handling logic rather than a direct attack by external threat actors
Timeline
- 2026-02-23 Breach occurred
- 2026-02-23 Publicly disclosed