PAYPAL, INC.
bd_add16c56f5a6da9d · schema v1 · pii pii-v1
Full breach record for PAYPAL, INC. →3 incidents on filePayPal, Inc. experienced a credential stuffing attack where an unauthorized party gained access to user accounts by using credentials stolen from other websites. The breach occurred on December 6, 2022, and was discovered on December 20, 2022. The compromised information included names and Social Security numbers. Affected individuals were notified on January 18, 2023, and offered 24 months of identity protection and credit monitoring services from Equifax.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 6, 2022
Begins
Dec 20, 2022
Discovered
Jan 18, 2023
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_2381991d8ce7e2422023-01-18Verified
- Washington State AGbd_23c5745c2f3389382023-01-18Verified
- California State AGbd_523acb840ed66f312023-01-18Verified
- Indiana State AGbd_622a569cab26bff72023-01-18Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Oregon State AGbd_a2e5f3a545f483792023-01-18Verified
- New Hampshire State AGbd_b77eec4b92da362d2023-01-17 · +1dCandidate
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.