Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationmass-credential-exposurefinancial-sector-threat

PayPal Working Capital Loan App Coding Error Exposed Customer PII

Updated 3mo agoFirst seen Feb 21, 202610 sources

PayPal disclosed that a coding error in its PayPal Working Capital (PPWC) loan application exposed a small number of customers’ personally identifiable information (PII) to unauthorized parties for roughly six months (July 1 to December 13, 2025). The exposed data included business contact details (name, email, phone number, business address) and highly sensitive identifiers such as Social Security numbers and dates of birth; PayPal said its core systems were not compromised and that the issue stemmed from an internal software defect that was later rolled back.

PayPal detected the exposure on December 12, 2025, initiated an investigation, blocked the unauthorized access, and required password resets/new credentials for impacted accounts. A small number of affected customers reported unauthorized transactions, which PayPal said were refunded; reporting indicates approximately 100 customers were notified. PayPal also stated the notification was not delayed by law enforcement and is offering impacted individuals two years of credit monitoring/identity restoration services (via Equifax, per reporting) alongside strengthened security checks.

Share:
PayPal Working Capital Loan App Coding Error Exposed Customer PII
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 10, 20264mo ago

PayPal offers two years of Equifax identity protection

As part of its remediation, PayPal offered affected customers two years of credit monitoring and identity restoration services through Equifax. Enrollment for the service was made available following the February 2026 notification.

PayPal sends breach notices to affected customers

PayPal issued written breach notifications from its San Jose headquarters to impacted customers, disclosing the six-month exposure and available remediation. The notices said a small number of customers had unauthorized transactions, which PayPal refunded.

Dec 13, 20256mo ago

PayPal rolls back faulty code and ends exposure

PayPal rolled back the code change in the PPWC interface, terminated unauthorized access, reset affected passwords, and added stronger login/security controls. The company said the exposure ended by December 13, 2025.

Dec 12, 20256mo ago

PayPal detects unauthorized activity in loan application

PayPal discovered the unauthorized activity and identified the underlying application error affecting PPWC customer data. The company said the issue was detected on December 12, 2025.

Jul 1, 20251y ago

PPWC loan app code change begins exposing customer data

A coding error in PayPal's PayPal Working Capital loan application began exposing customer personal and business information, including Social Security numbers and dates of birth, to unauthorized access. The exposure window started on July 1, 2025 and ultimately affected about 100 customers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Affected products
2 linked
PaypalGoogle Search
Organizations
8 linked
PayPalEquifaxShutterstockTransUnionBleepingComputerExperianDiscordLastPass
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

PayPal Working Capital Loan App Coding Error Exposed Customer PII | Mallory