What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
PayPal confirmed a limited data-security incident involving its PayPal Working Capital loan application—not a breach of every PayPal account. PayPal’s notice says a software error exposed information belonging to a small number of customers between July 1 and December 13, 2025. The information could have included names, contact details, business addresses, Social Security numbers and dates of birth. If you received an individual notice, follow it; if your login or money is being misused, secure your email and financial accounts and contact PayPal immediately.
What PayPal confirmed
According to the Massachusetts breach filing, PayPal identified an error in the PayPal Working Capital loan application on December 12, 2025. Unauthorized individuals could access records from July 1 through December 13, 2025. PayPal rolled back the code change, terminated the unauthorized access and notified affected customers in a notice dated February 10, 2026. The filing describes a small number of customers, not the entire PayPal customer base. Read the filing.
The notice says the exposed information could have included a customer’s name, email address, phone number, business address, Social Security number and date of birth. It does not say every recipient had every listed data element exposed. PayPal says a few customers experienced unauthorized transactions and received refunds, and that affected passwords were reset or subjected to an enhanced reset requirement.
PayPal’s privacy notice lists other information it may collect for particular products, such as balances, transaction history, credit history and credit scores. That general policy is not proof that those categories were part of this incident. See PayPal’s privacy notice.
#1 Best Overall
Was PayPal hacked?
The most accurate description is: PayPal confirmed a data-security incident involving its PayPal Working Capital application, but the available notice does not establish that the entire PayPal customer base was hacked.
Data exposure
A programming error made some Working Capital records accessible to unauthorized people. That is different from an attacker breaking into every PayPal account or stealing the company’s whole customer database.
Account takeover
An account takeover means someone gains control of your login, often through phishing, reused passwords, credential stuffing, malware, a compromised email account or a SIM swap. It can happen independently of the Working Capital incident.
Unauthorized transaction
A payment, transfer, withdrawal, refund, invoice or card charge you did not authorize is a separate event. Report it promptly even if you have no evidence that your personal information was in the Working Capital exposure.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteUnverified online claims
Reports about an alleged dataset affecting millions of PayPal users should not be merged with the confirmed Working Capital incident. One widely circulated 2025 report said PayPal attributed the data to a 2022 security incident rather than a newly confirmed 2025 platform breach. See that report’s attribution.
How to tell whether you were affected
- Look for a dated letter or email addressed specifically to you that identifies the PayPal Working Capital incident.
- Check which data elements PayPal says may have been involved; do not assume an SSN was exposed simply because you have a PayPal account.
- Look for Equifax monitoring and identity-restoration enrollment instructions and the stated deadline.
Do not use links in an unexpected message to investigate. Manually enter PayPal’s address or use the official app, then check the Message Center. You can also use the PayPal U.S. Security Center.
If your SSN or date of birth may have been exposed
1. Check your credit reports
Obtain reports from all three bureaus at AnnualCreditReport.com, the federally authorized source. Look for unfamiliar accounts, hard inquiries, collection accounts, address changes, loans or cards you did not open and incorrect personal information. The FTC recommends this review when an SSN may have been exposed. Read the FTC guidance.
2. Decide between a freeze and a fraud alert
A credit freeze is free, does not affect your score and restricts prospective creditors from accessing your file. Place it separately with each bureau and lift it temporarily when you legitimately apply for credit. It does not stop takeover of an existing account, phishing, tax fraud or every form of identity theft.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →A fraud alert is less restrictive: it asks lenders to take extra steps to verify you. PayPal says placing one bureau’s alert should notify the other two. PayPal fraud-reporting guidance. Choose a freeze when prevention is the priority or you see suspicious inquiries; choose an alert when you want less disruption while applying for credit.
3. Monitor other identity signals
Watch for unexpected IRS notices or tax returns, unemployment or other benefit claims, employment or wage records and medical bills or insurance claims you do not recognize. These are possible consequences of SSN misuse, not evidence that PayPal’s notice says they occurred.
4. Check the offered Equifax remedy
The February 10, 2026 notice offered two years of complimentary three-bureau monitoring and identity restoration, with an enrollment deadline of June 30, 2026. That deadline has passed. Contact PayPal or follow the support instructions in your notice to ask whether late enrollment or another remedy is available; do not assume enrollment remains open.
If your PayPal account was taken over
When you can still sign in
- Change your PayPal password to a unique password that you have never used elsewhere.
- Change the password for the associated email account and secure its recovery details, forwarding rules and active sessions.
- Remove unfamiliar email addresses, phone numbers, shipping addresses, bank accounts, cards and security settings from PayPal.
- Review recent activity, automatic payments, transfers, refunds, invoices and withdrawals.
- Report unauthorized transactions through PayPal’s Resolution Center and fraud-reporting page.
- Contact the linked bank or card issuer using its official app or the number on the card.
- Enable two-step verification and other available security controls.
- Change any reused password on banking, shopping, social-media and password-manager accounts.
When you cannot sign in
Use the official Security Center or Help Center and state that the account was taken over. PayPal says it may temporarily freeze an account when unauthorized access is suspected. See PayPal’s unauthorized-access instructions.
Best Value
Do not keep sending password resets to an old email address if the attacker changed it. Do not call numbers supplied in suspicious messages. Preserve screenshots, transaction IDs, dates, emails, usernames and support-case numbers. Do not create duplicate accounts to evade a security hold.
If money was taken
- Report the transaction to PayPal immediately.
- Call the bank or credit union that funded it.
- Contact the credit-card issuer if a card was used.
- Use IdentityTheft.gov, IC3 or local law enforcement when identity theft or a broader crime is involved.
PayPal has separate reporting routes for PayPal Credit, PayPal debit cards and PayPal-branded cards. Reimbursement is not automatic; eligibility depends on the transaction and applicable terms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to spot a breach-related phishing scam
Breach notices create ideal conditions for impersonation. Treat a message as suspicious if it demands your SSN or full bank password, asks you to move money to a “safe” account, requests a one-time code or remote-access software, uses a shortened link or attachment, threatens immediate closure, or provides a phone number that does not appear on PayPal’s official site.
Do not reply. Open the PayPal Security Center independently and use its suspicious-message reporting option. PayPal will not need you to disclose a password or move funds to protect an account.
Free tools Windows power users keep installed
One-click scans. No signup required.
What monitoring can—and cannot—do
| Tool | What it does | What it cannot do |
|---|---|---|
| Credit monitoring | Alerts you to certain changes on credit reports. | Prevent account takeover or make an exposed SSN secret again. |
| Credit freeze | Restricts most prospective-credit access until you lift it. | Stop misuse of existing accounts, phishing, tax fraud or every identity crime. |
| Fraud alert | Asks lenders to verify your identity more carefully. | Block applications as comprehensively as a freeze. |
| Identity restoration | May help with paperwork and recovery after fraud. | Guarantee prevention or prove that exposed data is being misused. |
Start with free reports, freezes and any remedy in your notice. Paid monitoring may duplicate these services; consider it only if you value additional alerts, restoration help or family coverage.
Product and location limits
The cited filing is a U.S. notice filed with Massachusetts and is most directly applicable to affected U.S. recipients. PayPal Credit, debit cards, Cashback Mastercard, Business Debit Mastercard and ordinary PayPal accounts can have different reporting routes. Customers outside the United States may have different bureaus, remedies and reporting agencies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




