PAYPAL, INC.
ent_019e24254e0b9db9cadf0200c980852d
Disclosures
10
State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
34,942
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PAYPAL, INC.
- Normalized
- paypal— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- LBQ3CAGQB6M55WHL3G85
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- PAYPAL HOLDINGS, INC.— per GLEIF relationship records
Disclosure history (10)newest first
- Massachusetts State AGas victim2026-02-19
PayPal disclosed that an error in its PayPal Working Capital loan application exposed PII (name, email, phone, business address, SSN, DOB) of a small number of customers between July 1, 2025, and December 13, 2025. The incident was discovered on December 12, 2025. PayPal rolled back the code change, terminated unauthorized access, reset passwords, and offered two years of credit monitoring.
- Nebraska State AGas victim2026-02-19
PayPal Inc notified Nebraska residents of a data breach involving a PayPal Working Capital loan application error. Unauthorized access occurred between July 1, 2025, and December 13, 2025. Exposed data included names, contact info, SSNs, dates of birth, and financial account numbers. PayPal rolled back the code change, reset passwords, issued refunds for unauthorized transactions, and offered two years of credit monitoring via Equifax.
- Massachusetts State AGas victim2023-01-18
PayPal, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-01-18. 630 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-01-18
PayPal, Inc. notified Washington AG of a credential stuffing incident affecting 890 Washington residents. Unauthorized access occurred Dec 6-8, 2022, using credentials obtained via phishing unrelated to PayPal. Exposed data included names, addresses, SSNs, and DOBs. PayPal contained the breach, reset passwords, and offered 24 months of credit monitoring.
- California State AGas victim2023-01-18
PayPal confirmed unauthorized access to customer accounts using login credentials between Dec 6-8, 2022. The incident was discovered on Dec 20, 2022. Affected data may include name, address, SSN, ITIN, and DOB. PayPal reset passwords, implemented enhanced security controls, and offered two years of Equifax identity monitoring. No evidence suggests credentials were obtained from PayPal systems.
- Indiana State AGas victim2023-01-18
Paypal, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-12-06 and was reported on 2023-01-18. 824 Indiana residents were affected. 34,942 individuals affected in total.
- Oregon State AGas victim2023-01-18
PayPal, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-18. The breach occurred during 12/6/2022 - 12/8/2022. The breach was discovered on 12/20/2022. 34,942 individuals were affected. Notice was sent on 1/18/2023.
- Maine State AGas victim2023-01-18
PayPal, Inc. experienced a credential stuffing attack where an unauthorized party gained access to user accounts by using credentials stolen from other websites. The breach occurred on December 6, 2022, and was discovered on December 20, 2022. The compromised information included names and Social Security numbers. Affected individuals were notified on January 18, 2023, and offered 24 months of identity protection and credit monitoring services from Equifax.
- New Hampshire State AGas victim2023-01-17
PayPal, Inc. notified the New Hampshire Attorney General of a credential stuffing incident affecting 145 NH residents. Unauthorized access occurred Dec 6-8, 2022, using credentials obtained via phishing unrelated to PayPal. Exposed data included names, SSNs, and DOBs. PayPal reset passwords, engaged counsel, and offered 24 months of Equifax monitoring.
- New Hampshire State AGas victim2019-09-09
PayPal Inc. notified the NH Attorney General of a vendor-insider fraud scheme impacting 67 Venmo accounts. Vendor employees misused customer data to facilitate unauthorized access and transactions. Discovered Aug 8, 2019. Notifications sent Sept 6, 2019. Affected data included names, emails, phone numbers, and partial financial account details. 1 NH resident affected.