PAYPAL, INC.
ent_019e24254e0b9db9cadf0200c980852d
Disclosures
4
State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
34,942
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PAYPAL, INC.
- Normalized
- paypal— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- LBQ3CAGQB6M55WHL3G85
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- PAYPAL HOLDINGS, INC.— per GLEIF relationship records
Disclosure history (4)newest first
- 🌲Washington State AGas victim2023-01-18
PayPal, Inc., a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2022-12-08 and filed notice on 2023-01-18. 890 Washington residents were affected. 41 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2023-01-18
PayPal confirmed unauthorized access to customer accounts using login credentials between Dec 6-8, 2022. The incident was discovered on Dec 20, 2022. Affected data may include name, address, SSN, ITIN, and DOB. PayPal reset passwords, implemented enhanced security controls, and offered two years of Equifax identity monitoring. No evidence suggests credentials were obtained from PayPal systems.
- 🦫Oregon State AGas victim2023-01-18
PayPal, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-18. The breach occurred during 12/6/2022 - 12/8/2022. The breach was discovered on 12/20/2022. 34,942 individuals were affected. Notice was sent on 1/18/2023.
- 🦞Maine State AGas victim2023-01-18
PayPal, Inc. experienced a credential stuffing attack where an unauthorized party gained access to user accounts by using credentials stolen from other websites. The breach occurred on December 6, 2022, and was discovered on December 20, 2022. The compromised information included names and Social Security numbers. Affected individuals were notified on January 18, 2023, and offered 24 months of identity protection and credit monitoring services from Equifax.