What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
A software error in PayPal’s Working Capital loan application may have exposed some customers’ personal information, including Social Security numbers, from July 1 through December 13, 2025. PayPal says it notified a small number of customers; the incident is not evidence that every PayPal account or the company’s entire payment platform was breached. The enrollment deadline for the complimentary Equifax services in PayPal’s notice was June 30, 2026, so it has passed.
What happened in the PayPal incident?
PayPal attributed the exposure to an error in its PayPal Working Capital (PPWC) loan application. The company said the error made some customers’ information accessible to unauthorized individuals during the period from July 1 to December 13, 2025. PayPal identified the issue on December 12 and said it rolled back the code change and terminated the unauthorized access on December 13. The customer notice, filed with Massachusetts, says notification was not delayed because of a law-enforcement investigation. Read PayPal’s official notice.
PayPal Working Capital is financing for eligible PayPal business or Premier-account holders, with eligibility tied in part to account history and sales. It is distinct from ordinary PayPal checkout use. PayPal’s Working Capital page describes the product.
What information may have been exposed?
PayPal said the information could have included the following fields. That wording does not establish that every field was exposed for every affected person:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Name
- Email address
- Phone number
- Business address
- Social Security number
- Date of birth
The notice says a “small number of customers” were affected, but does not provide a definitive count. BleepingComputer reported an estimate of about 100 customers; treat that as secondary reporting, not PayPal’s official total. BleepingComputer’s report.
Was PayPal hacked, and were accounts misused?
The official notice describes an application error that exposed information to unauthorized individuals. It does not establish a compromise of PayPal’s entire infrastructure or core payment systems, so describing this as a hack of all PayPal accounts would go beyond the evidence.
Exposure, account access, and financial fraud are different outcomes. PayPal said a few customers experienced unauthorized transactions and that it refunded them. This confirms some account misuse, but the cited notices do not establish widespread identity theft or that every exposed record was copied or used. SecurityWeek also reported the unauthorized transactions.
Who should check whether they were affected?
The incident was tied to the Working Capital application, not to PayPal users generally. The clearest indication that you were included is receiving a formal PayPal breach notification. If you used or applied for Working Capital during the exposure period but have not seen a notice, contact PayPal through its official website or app rather than relying on an unexpected email or text. There is no evidence in the notice that every merchant or ordinary consumer account was affected.
What did PayPal do, and can you still claim its free monitoring?
PayPal said it investigated the issue, terminated unauthorized access, rolled back the code change, reset passwords for affected accounts, and added controls requiring affected users to establish a new password at their next login. It also said it refunded a few unauthorized transactions. The notice offered notified customers two years of complimentary three-bureau credit monitoring and identity-restoration services through Equifax.
The stated enrollment deadline was June 30, 2026. If you received a notice but missed that date, contact PayPal using an official support channel and ask whether an extension or alternative assistance is available; do not assume late enrollment will be accepted. Treat unsolicited messages offering to reopen enrollment as suspicious.
What affected customers should do now
- Verify any breach notice independently. Do not use a link or phone number in an unexpected message. Sign in through PayPal’s official app or type its known address yourself, then contact support if you need to confirm the notice.
- Review PayPal activity and payment methods. Check recent transactions, linked bank accounts and cards, profile details, and security-setting changes for anything unfamiliar.
- Report unauthorized activity promptly. Contact PayPal immediately if you suspect someone accessed your account, and report unauthorized payments through its Resolution Center. See PayPal’s guidance on unauthorized access.
- Replace reused passwords. Change your PayPal password and any other password that is the same or similar, including the password for the email account associated with PayPal. Use unique passwords and enable multifactor authentication where available.
- Check your credit reports. Review reports for unfamiliar accounts or inquiries. Use the federally authorized AnnualCreditReport.com service rather than links in unsolicited messages.
- Consider a credit freeze or fraud alert. A freeze restricts access to your credit file until you lift it; a fraud alert asks prospective creditors to take extra steps to verify your identity. Credit monitoring can flag changes, but it does not itself prevent new-account fraud. PayPal’s notice points readers to FTC identity-theft guidance.
- Be alert for targeted phishing. The combination of contact, business, and identity details could make a scam more convincing, but that risk is not proof your information has already been misused. Do not share passwords, Social Security numbers, or one-time login codes with callers or message senders. Verify any claim by contacting PayPal through an official channel.
What this incident does not establish
- That every PayPal user, merchant, or consumer account was affected.
- That PayPal’s entire payment platform was compromised.
- That every listed data field was exposed for every notified customer.
- That all exposed information was copied, sold, or used for identity theft.
- A definitive affected-customer count; PayPal’s notice says only “a small number.”
Frequently Asked Questions
Should I close my PayPal account?
The incident alone does not establish that every PayPal account was affected. If you received a notice, review activity, secure the account, and contact PayPal about anything suspicious; decide whether to keep the account based on your circumstances.
How can I recognize a fake PayPal breach message?
Do not trust a message simply because it mentions this incident. Avoid unexpected claim links and requests for passwords, one-time codes, or payment. Confirm notices and offers by contacting PayPal through its official app or website.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




