RegulationFor CFOAction Required Within 90 Days

PayPal coding bug led to unauthorised access to business accounts

Coding bug exposed customer data for six months; unauthorized transactions detected

The Ledger Signal | Analysis
Verified
0
1
PayPal coding bug led to unauthorised access to business accounts

Why This Matters

Why this matters: Finance leaders using PayPal's Working Capital loan app need to assess exposure and review transaction controls for unauthorized activity.

PayPal coding bug led to unauthorised access to business accounts

PayPal disclosed a data breach affecting its Working Capital loan app that exposed sensitive customer information including names, emails, Social Security numbers, and dates of birth for six months (July-December 2025). The coding bug also led to unauthorized transactions before being discovered and patched on December 13, 2025. PayPal has reset passwords and offered affected customers two years of complimentary credit monitoring and identity restoration services.

Originally Reported By
Finextra

Finextra

finextra.com

Why We Covered This

Finance teams relying on PayPal's Working Capital loan app must evaluate the breach's impact on transaction integrity, reconciliation processes, and internal controls over financial reporting.

Key Takeaways
PayPal disclosed a data breach affecting its Working Capital loan app that exposed sensitive customer information including names, emails, Social Security numbers, and dates of birth for six months (July-December 2025)
The coding bug also led to unauthorized transactions before being discovered and patched on December 13, 2025
PayPal has reset passwords and offered affected customers two years of complimentary credit monitoring and identity restoration services
CompaniesPayPal(PYPL)
Key DatesIncident Start:2025-07-01Remediation:2025-12-13Incident End:2025-12-31
Affected Workflows
Vendor ManagementAudit
D
WRITTEN BY

David Okafor

Treasury and cash management specialist covering working capital optimization.

Responses (0 )