PayPal Data Breach Settlement: $2M NY Fine and Class Action

PayPal’s data breach settlement with New York regulators, announced on January 23, 2025, required the company to pay a $2 million civil penalty over a December 2022 credential-stuffing attack that exposed sensitive tax-form information for roughly 34,942 customers.1New York State Department of Financial Services. DFS Announces PayPal Settlement A separate federal class action filed by affected customers was terminated in May 2023 without a public settlement on the record.2CourtListener. Pillard v. PayPal, Inc. – Parties

What Happened in the 2022 Breach

Between December 6 and December 8, 2022, attackers used credentials stolen from unrelated breaches to log into PayPal accounts, a technique called credential stuffing.3Cybersecurity Dive. PayPal Credential Stuffing Attack PayPal’s team saw a spike in unauthorized login attempts on December 7 but did not fully scope the incident until December 20, 2022.4The Record. PayPal Penalty Millions Data Breach

Once inside, the attackers reached IRS Form 1099-K documents stored on the platform. Those forms contained unmasked names, addresses, Social Security numbers, tax ID numbers, dates of birth, and phone numbers.5American Banker. NYDFS Penalizes PayPal $2M Over 2022 Data Breach PayPal said its payment systems were not compromised and that no financial account information was accessed.3Cybersecurity Dive. PayPal Credential Stuffing Attack

Why New York Regulators Fined PayPal

The New York State Department of Financial Services traced the exposure to a change PayPal made to expand access to 1099-K forms for more customers. Engineering teams treated the change as a routine platform migration rather than a new product capability, so it skipped standard risk assessments, penetration tests, and vulnerability scans.5American Banker. NYDFS Penalizes PayPal $2M Over 2022 Data Breach The staff involved were not adequately trained on PayPal’s own cybersecurity policies.1New York State Department of Financial Services. DFS Announces PayPal Settlement

Sensitive data on the forms sat unmasked, and PayPal did not require multifactor authentication for U.S. accounts or use CAPTCHA and rate limiting to block automated logins.5American Banker. NYDFS Penalizes PayPal $2M Over 2022 Data Breach A PayPal security analyst reportedly found the vulnerability after coming across an online post explaining how to pull Social Security numbers from the site.6FKKS Technology Law. NYDFS Imposes $2 Million Fine on PayPal for Cybersecurity Violations

DFS found PayPal violated three provisions of New York’s cybersecurity regulation, 23 NYCRR Part 500:

  • Section 500.10, for using unqualified personnel on key cybersecurity functions and failing to train the engineering team involved in the 1099-K change.
  • Section 500.3, for not properly implementing written policies covering access controls, identity management, and customer data privacy.
  • Section 500.12, for lacking effective access controls, including mandatory multifactor authentication, CAPTCHA, and rate limiting.

The findings were set out in a consent order the company signed.7New York State Department of Financial Services. Consent Order: PayPal, Inc.

What the $2 Million Settlement Required PayPal to Change

The $2 million payment was the headline number, but the consent order also locked in security changes PayPal confirmed it had already made. Multifactor authentication is now required for all U.S. customer account logins, reversing the pre-breach practice of leaving MFA optional.7New York State Department of Financial Services. Consent Order: PayPal, Inc. PayPal deployed CAPTCHA and rate-limiting technology to block automated login attempts, and DFS said those controls “successfully stopped the automated account access to unmasked” customer information.1New York State Department of Financial Services. DFS Announces PayPal Settlement

The company also masked the sensitive data on the 1099-K forms, revised its internal rules on when a product change triggers a risk assessment, and gave targeted cybersecurity training to the engineering team behind the original mistake.7New York State Department of Financial Services. Consent Order: PayPal, Inc.

The Consumer Class Action

Two PayPal customers, Ashley Pillard and Destiny Rucker, filed a federal class action on March 2, 2023, in the U.S. District Court for the Northern District of California. The case, Pillard v. PayPal, Inc., No. 5:23-cv-00936, alleged that PayPal failed to implement basic security practices and to follow industry standards including FTC guidance and the NIST Cybersecurity Framework.8Bloomberg Law. PayPal Hit With Class Action Over Data Breach Affecting 35,000 The plaintiffs asserted negligence, negligence per se, and breach of contract, and asked for damages, lifetime credit monitoring, and identity theft insurance.

Court records show the case was terminated on May 15, 2023, roughly two and a half months after filing.2CourtListener. Pillard v. PayPal, Inc. – Parties There is no public settlement, class certification, or published opinion on the record, and no separate FTC enforcement action against PayPal over the breach appears in the available sources.

What Affected Customers Received

PayPal reset the passwords on all affected accounts and required those customers to create new credentials.3Cybersecurity Dive. PayPal Credential Stuffing Attack Notification letters went out in January 2023, and the company offered two years of free identity monitoring through Equifax.4The Record. PayPal Penalty Millions Data Breach The $2 million penalty went to New York State, not to individual consumers, and the terminated class action did not produce a payout of record.

Other PayPal Incidents That Are Not Part of This Settlement

Two later events sometimes get grouped with the 2022 breach but are separate. In August 2025, a threat actor advertised 15.8 million PayPal credentials on a hacker forum, claiming the data came from a May 2025 breach. PayPal denied a new breach, saying the claims were “related to an incident that occurred in 2022 and not new,” and researchers could not verify the seller’s claim, with some suggesting the credentials came from infostealer malware on individual devices rather than PayPal’s systems.9Hackread. Threat Actor Selling Plain Text PayPal Credentials10Cybernews. PayPal Credential Dump Hacker Claims

In February 2026, PayPal disclosed a different incident tied to its Working Capital loan application, where a coding flaw introduced during a software update exposed customer data between July 1, 2025, and December 13, 2025. Exposed information included names, email addresses, phone numbers, business addresses, dates of birth, and in some cases Social Security numbers.11Reflectiz. PayPal Breach 202612Cyberpress. PayPal Data Breach As of mid-2026, no regulatory penalties or lawsuits tied to the Working Capital incident had been announced.13Bright Defense. PayPal Breach