
Nearly 35,000 accounts of leading electronic payments platform PayPal were breached in a large-scale credential stuffing attack between December 6 and December 8, 2022, that exposed some personal data.
PayPal’s report on the data breach said that the cyber incident impacted 34,942 users. Hackers had access to the full names, birthdates, postal addresses, social security numbers, and unique tax identification numbers of account holders for the two days. The incident also exposed transaction histories, PayPal invoicing data, and connected credit or debit card details.
As soon as the company detected the attack, it started an internal investigation on December 20, 2022, to find out how the hackers obtained access to the accounts and confirmed that unauthorized individuals used legitimate login information to access the accounts. PayPal has started sending out data breach notifications to the affected users.
Additionally, PayPal claimed that it acted swiftly to restrict the hackers’ access to the system and change the passwords of the confirmed compromised accounts. The notification also stated that the attackers attempted or completed no transactions from the compromised PayPal accounts. The affected users will get a free two-year subscription to Equifax’s identity monitoring service.
The company urged recipients of the notices to change their passwords for additional online accounts, advising them to use a long and distinctive string. Additionally, PayPal suggested that users turn on two-factor authentication (2FA) security.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543