PayPal is notifying customers of a data breach linked to a software bug in its lending app, PayPal Working Capital. The technical issue resulted in the exposure of sensitive personal information for nearly six months in 2025, putting security concerns back in the spotlight in the fintech industry.
PayPal: The bug that left personal data exposed
According to the company, the incident was discovered on December 12, 2025, and involved the PayPal Working Capital (PPWC) app, which offers rapid financing to small businesses. The internal investigation showed that from July 1, 2025, to December 13, 2025, unauthorized individuals were able to access information such as names, emails, phone numbers, business addresses, dates of birth and — most worryingly — Social Security numbers.
See also: French National Bank Authority: 1.2 million accounts breached
PayPal said the issue was caused by a code change to its lending platform and that the change was rolled back within 24 hours of discovery. As noted in the letters to affected users, the company did not delay the update due to a law enforcement investigation.

Economic impacts and immediate actions
In addition to the data exposure, the company also found unauthorized transactions on a limited number of accounts that were directly linked to the incident. Affected customers received refunds, while PayPal reset passwords for all accounts that were deemed vulnerable.
The next time users log in, they are prompted to create new credentials, further enhancing the level of security. The company also reminded users that it never asks for passwords, one-time codes, or other identifying information over the phone, SMS, or email — a critical point, as breaches are often followed by waves of phishing attacks.
Free credit monitoring through Equifax
As a remedial measure, PayPal is offering two years of free credit monitoring and identity restoration through Equifax. The package covers all three major credit reporting agencies, with a deadline to sign up by June 30, 2026.
See also: Cyberattack at University of Mississippi Medical Center leads to clinic closures
This practice is now almost standard procedure in cases of sensitive data leaks, but it does not negate the risk that arises when data such as social security numbers get out of control. Experts emphasize that continuous monitoring of credit reports and bank transactions is necessary, especially in the first months after such incidents.

Incident history and regulatory pressures
The 2025 incident is not the first for PayPal. In January 2023, the company disclosed a breach related to a large-scale attack credential stuffing, which led to the compromise of approximately 35,000 accounts in December 2022.
The fallout from that case extended to the regulatory level. In January 2025, New York State announced a $2 million settlement with PayPal, accusing the company of failing to comply with cybersecurity regulations that apply to financial institutions in the state.
See also: Tenga: Sex toy manufacturer victim of data breach
The recurrence of incidents, even with a different technical cause, intensifies pressure on fintech companies to invest more in secure software development (secure SDLC), code reviews, and error prevention mechanisms before releasing updates.
The broader message for the fintech industry
The case highlights a critical challenge for digital financial services: speed and innovation cannot come at the expense of security. Platforms like PayPal Working Capital handle highly sensitive data of entrepreneurs and professionals, making them attractive targets.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In an environment where cyberattacks are increasing and regulatory requirements are tightening, trust is the most valuable currency. For companies the size of PayPal, every technical error instantly becomes a test of reliability.
Whether the rapid response and remediation measures are sufficient to maintain that trust will be judged in the coming months. What is certain is that the incident serves as a reminder that in the digital economy, security is not an option — it is a requirement.
Source: www.bleepingcomputer.com
