PAYPAL, INC.
bd_23c5745c2f338938 · schema v1 · pii pii-v1
Full breach record for PAYPAL, INC. →3 incidents on filePayPal, Inc. notified Washington AG of a credential stuffing incident affecting 890 Washington residents. Unauthorized access occurred Dec 6-8, 2022, using credentials obtained via phishing unrelated to PayPal. Exposed data included names, addresses, SSNs, and DOBs. PayPal contained the breach, reset passwords, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 6, 2022
Begins
Dec 8, 2022
Discovered
Jan 18, 2023
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_2381991d8ce7e2422023-01-18Verified
- California State AGbd_523acb840ed66f312023-01-18Verified
- Indiana State AGbd_622a569cab26bff72023-01-18Verified
- Oregon State AGbd_a2e5f3a545f483792023-01-18Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Maine State AGbd_add16c56f5a6da9d2023-01-18Verified
- New Hampshire State AGbd_b77eec4b92da362d2023-01-17 · +1dCandidate
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.