PayPal
Disclosed Jan 18, 20233 years ago34,942 affectedConfirmed
Credential stuffing attack exposes Social Security numbers in PayPal accounts
PayPal notified customers that unauthorized parties logged into accounts with valid credentials obtained elsewhere between December 6 and 8, 2022. They could view names, addresses, Social Security or tax ID numbers and dates of birth; PayPal reset the affected accounts' passwords.
What is known
| People affected | 34,942 (as reported by the organization) |
|---|---|
| Disclosed | Jan 18, 2023 |
| Discovered | Dec 8, 2022 |
| Happened | Dec 6, 2022 |
| Attack | Credential stuffing |
| Data exposed | Names, Addresses, Social Security numbers, Dates of birth |
| Sector | Finance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: PayPaloag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: PayPalatg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: PayPaljustice.oregon.gov · Official notice | Official notice |
| California AG data breach notice: PayPal, Inc.oag.ca.gov · Regulator | Regulator |
| Indiana Attorney General 2023 data breach report: Paypalin.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jan 18, 2023 | |
| Washington AGresidents of WA | Jan 18, 2023 | 890 |
| Oregon DOJresidents of OR | Jan 18, 2023 | 34,942 |
| Researchtotal | Jan 18, 2023 | |
| Indiana AGresidents of IN | Jan 18, 2023 | 824 |
Other breaches at PayPal
| Breach | Affected | ||||
|---|---|---|---|---|---|
| PayPal Working Capital code error exposed SSNs of about 100 customersFeb 207 months agoExposed dataUnverified | Feb 207 months ago | Exposed data | Finance | Unverified | 100 |
History of this record
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 34942 · backfill source
- 2026-09-25 · attack: hacking to credential-stuffing · seed source
- 2026-09-25 · data_types: [] to ["names","addresses","ssn","dob"] · seed source
- 2026-09-25 · summary: empty to PayPal notified customers that unauthorized parties logged into accounts with valid credentials obtained elsewhere between December 6 and 8, 2022. They could view names, addresses, Social Security or tax ID numbers and dates of birth; PayPa · seed source
- 2026-09-25 · title: empty to Credential stuffing attack exposes Social Security numbers in PayPal accounts · seed source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · discovered: empty to 2022-12-08 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.