PAYPAL, INC.
bd_b77eec4b92da362d · schema v1 · pii pii-v1
Full breach record for PAYPAL, INC. →3 incidents on filePayPal, Inc. notified the New Hampshire Attorney General of a credential stuffing incident affecting 145 NH residents. Unauthorized access occurred Dec 6-8, 2022, using credentials obtained via phishing unrelated to PayPal. Exposed data included names, SSNs, and DOBs. PayPal reset passwords, engaged counsel, and offered 24 months of Equifax monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 6, 2022
Begins
Dec 8, 2022
Discovered
Jan 17, 2023
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Massachusetts State AGbd_2381991d8ce7e2422023-01-18 · +1dVerified
- Washington State AGbd_23c5745c2f3389382023-01-18 · +1dVerified
- California State AGbd_523acb840ed66f312023-01-18 · +1dVerified
- Indiana State AGbd_622a569cab26bff72023-01-18 · +1dVerified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- Oregon State AGbd_a2e5f3a545f483792023-01-18 · +1dVerified
- Maine State AGbd_add16c56f5a6da9d2023-01-18 · +1dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.