Clustered 4 filings across 4 jurisdictions · filed Jan 18, 2023. View entity profile → Other incidents for this victim →
incident inc_5a7736b6a09a42b7 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA ME OR WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Dec 6, 2022 → Dec 8, 2022
When the intrusion reportedly occurred, per the linked filings
Dec 8, 2022
Reported by WASHINGTON AG filing
Dec 20, 2022
Reported by CALIFORNIA AG, OREGON AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
PayPal, Inc., a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2022-12-08 and filed notice on 2023-01-18. 890 Washington residents were affected. 41 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 890
PayPal confirmed unauthorized access to customer accounts using login credentials between Dec 6-8, 2022. The incident was discovered on Dec 20, 2022. Affected data may include name, address, SSN, ITIN, and DOB. PayPal reset passwords, implemented enhanced security controls, and offered two years of Equifax identity monitoring. No evidence suggests credentials were obtained from PayPal systems.
PayPal, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-18. The breach occurred during 12/6/2022 - 12/8/2022. The breach was discovered on 12/20/2022. 34,942 individuals were affected. Notice was sent on 1/18/2023.
Affected (this filing): 34,942
PayPal, Inc. experienced a credential stuffing attack where an unauthorized party gained access to user accounts by using credentials stolen from other websites. The breach occurred on December 6, 2022, and was discovered on December 20, 2022. The compromised information included names and Social Security numbers. Affected individuals were notified on January 18, 2023, and offered 24 months of identity protection and credit monitoring services from Equifax.
Affected (this filing): 146