PAYPAL HOLDINGS, INC.
ent_019e581da40421ffb7703f85ea0ae442
Disclosures
1
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
3
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PAYPAL HOLDINGS, INC.
- Normalized
- paypal holdings— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493005X2GO78EFZ3E94
- SEC EDGAR CIK
- 0001633917
- Domain
- None on record
Disclosure history (1)newest first
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of PAYPAL HOLDINGS, INC. — not by PAYPAL HOLDINGS, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia PAYPAL, INC.2026-02-19
PayPal disclosed that an error in its PayPal Working Capital loan application exposed PII (name, email, phone, business address, SSN, DOB) of a small number of customers between July 1, 2025, and December 13, 2025. The incident was discovered on December 12, 2025. PayPal rolled back the code change, terminated unauthorized access, reset passwords, and offered two years of credit monitoring.
- Nebraska State AGvia PAYPAL, INC.2026-02-19
PayPal Inc notified Nebraska residents of a data breach involving a PayPal Working Capital loan application error. Unauthorized access occurred between July 1, 2025, and December 13, 2025. Exposed data included names, contact info, SSNs, dates of birth, and financial account numbers. PayPal rolled back the code change, reset passwords, issued refunds for unauthorized transactions, and offered two years of credit monitoring via Equifax.
- Massachusetts State AGvia PAYPAL, INC.2023-01-18
PayPal, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-01-18. 630 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGvia PAYPAL, INC.2023-01-18
PayPal, Inc. notified Washington AG of a credential stuffing incident affecting 890 Washington residents. Unauthorized access occurred Dec 6-8, 2022, using credentials obtained via phishing unrelated to PayPal. Exposed data included names, addresses, SSNs, and DOBs. PayPal contained the breach, reset passwords, and offered 24 months of credit monitoring.
- California State AGvia PAYPAL, INC.2023-01-18
PayPal confirmed unauthorized access to customer accounts using login credentials between Dec 6-8, 2022. The incident was discovered on Dec 20, 2022. Affected data may include name, address, SSN, ITIN, and DOB. PayPal reset passwords, implemented enhanced security controls, and offered two years of Equifax identity monitoring. No evidence suggests credentials were obtained from PayPal systems.
- Indiana State AGvia PAYPAL, INC.2023-01-18
Paypal, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2022-12-06 and was reported on 2023-01-18. 824 Indiana residents were affected. 34,942 individuals affected in total.
- Oregon State AGvia PAYPAL, INC.2023-01-18
PayPal, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-18. The breach occurred during 12/6/2022 - 12/8/2022. The breach was discovered on 12/20/2022. 34,942 individuals were affected. Notice was sent on 1/18/2023.
- Maine State AGvia PAYPAL, INC.2023-01-18
PayPal, Inc. experienced a credential stuffing attack where an unauthorized party gained access to user accounts by using credentials stolen from other websites. The breach occurred on December 6, 2022, and was discovered on December 20, 2022. The compromised information included names and Social Security numbers. Affected individuals were notified on January 18, 2023, and offered 24 months of identity protection and credit monitoring services from Equifax.
- New Hampshire State AGvia PAYPAL, INC.2023-01-17
PayPal, Inc. notified the New Hampshire Attorney General of a credential stuffing incident affecting 145 NH residents. Unauthorized access occurred Dec 6-8, 2022, using credentials obtained via phishing unrelated to PayPal. Exposed data included names, SSNs, and DOBs. PayPal reset passwords, engaged counsel, and offered 24 months of Equifax monitoring.
- New Hampshire State AGvia PAYPAL, INC.2019-09-09
PayPal Inc. notified the NH Attorney General of a vendor-insider fraud scheme impacting 67 Venmo accounts. Vendor employees misused customer data to facilitate unauthorized access and transactions. Discovered Aug 8, 2019. Notifications sent Sept 6, 2019. Affected data included names, emails, phone numbers, and partial financial account details. 1 NH resident affected.