PayPal discloses data breach that exposed user info for 6 months
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述就行。好的,我先仔细看看文章内容。 文章讲的是PayPal因为一个软件错误导致数据泄露,这个错误出现在他们的贷款申请系统里,持续了将近六个月。受影响的是PayPal Working Capital贷款应用的用户,主要是小企业主。PayPal是在2025年12月12日发现这个问题的,然后他们回滚了导致错误的代码变更,阻止了攻击者访问数据。被泄露的信息包括姓名、邮箱、电话号码、地址、社安号和出生日期。此外,还有少数用户的账户出现了未经授权的交易,PayPal已经退款,并提供了两年的免费信用监控和身份恢复服务。 用户还提到不需要特定的开头,所以直接描述事件即可。我需要确保在100字以内涵盖主要信息:数据泄露的原因、时间、受影响的信息类型、PayPal的应对措施以及提供的补救服务。 现在开始组织语言:PayPal因软件错误导致贷款应用数据泄露,持续近6个月,涉及姓名、邮箱、电话号码、地址、社安号和出生日期。发现后回滚代码阻止访问,并提供退款和两年免费信用监控服务。 检查字数是否在限制内:大约90字左右,符合要求。 </think> PayPal因软件错误导致贷款应用数据泄露近6个月,涉及姓名、邮箱、电话号码、地址、社安号和出生日期等信息。公司已回滚代码阻止访问,并提供退款及两年免费信用监控服务。 2026-2-20 13:15:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:4 收藏

PayPal

PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.

The incident affected the PayPal Working Capital (PPWC) loan app, which provides small businesses with quick access to financing.

PayPal discovered the breach on December 12, 2025, and determined that customers' names, email addresses, phone numbers, business addresses, Social Security numbers, and dates of birth had been exposed since July 1, 2025.

Wiz

The financial technology company said it has reversed the code change that caused the incident, blocking attackers' access to the data one day after discovering the breach.

"On December 12, 2025, PayPal identified that due to an error in its PayPal Working Capital ("PPWC") loan application, the PII of a small number of customers was exposed to unauthorized individuals during the timeframe of July 1, 2025 to December 13, 2025," PayPal said in breach notification letters sent to affected users.

"PayPal has since rolled back the code change responsible for this error, which potentially exposed the PII. We have not delayed this notification as a result of any law enforcement investigation."

PayPal also detected unauthorized transactions on the accounts of a small number of customers as a direct result of the incident and has issued refunds to those affected.

The company now offers affected users two years of free three-bureau credit monitoring and identity restoration services through Equifax, which require enrollment by June 30, 2026.

Affected customers are also advised to monitor their credit reports and their account activity for suspicious transactions. PayPal reminded users that it never requests account passwords, one-time codes, or other authentication credentials via phone, text, or email, a common tactic used in phishing attacks that often follow data breach disclosures.

While PayPal has yet to disclose how many customers were affected, it has reset passwords for all impacted accounts and said that users will be prompted to create new credentials upon their next login if they have not already done so.

BleepingComputer reached out to a PayPal spokesperson with questions about the incident, but a response was not immediately available.

In January 2023, PayPal notified customers of another data breach after a large-scale credential stuffing attack compromised 35,000 accounts between December 6 and December 8, 2022.

Two years later, in January 2025, New York State announced a $2,000,000 settlement with PayPal over charges that it failed to comply with the state's cybersecurity regulations, leading to the 2022 data breach.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/
如有侵权请联系:admin#unsafe.sh