Honest, In-Depth & Transparent VPN Reviews from Real Users

Honest, In-Depth & Transparent VPN Reviews

We may earn a commission from links. Learn more

Has PayPal Ever Been Hacked?

13-step review process Fact-checked

Last updated: September 7, 2026

Has PayPal Ever Been Hacked?

Key Takeaways

  • PayPal’s core payment platform has never been publicly confirmed as breached – but a company PayPal owns was.
  • One real breach happened in 2017, at TIO Networks – a subsidiary PayPal had recently acquired. It affected up to 1.6 million customers.
  • The 2022 incident that made headlines was not a hack of PayPal. Attackers used passwords leaked from other sites to open 34,942 accounts, or 0.008% of the user base.

PayPal handles money for hundreds of millions of people, so “has PayPal been hacked” is a fair thing to ask. The honest answer is more specific than most headlines suggest.

The Story Behind the Numbers

Two separate incidents get called “the PayPal hack,” and they are not the same kind of event.

The first was real. In late 2017, PayPal disclosed that attackers had breached TIO Networks, a bill-payment processor it acquired in July 2017, potentially compromising information belonging to up to 1.6 million customers. The affected data may have included names, addresses, bank account details, Social Security numbers and login information. PayPal stated that TIO’s systems were entirely separate from the PayPal network and that PayPal customer data was unaffected.

The second was different. Between December 6 and 8, 2022, unauthorized parties accessed nearly 35,000 PayPal accounts. PayPal discovered the access on December 20 and notified affected customers in January 2023, which is why the same event is sometimes called the 2023 breach. In a breach notification filed with the Maine Attorney General, PayPal said there was no evidence the login credentials were obtained through any company system.

Why This Data is Important

That second detail changes everything. The 34,942 affected accounts sat inside a base of 432 million active accounts – roughly 0.008% of users.

They were opened with credential stuffing. In this attack, a fraudster programmatically tries logging into a site using username and password pairs harvested from other breaches or phishing campaigns. Think of a burglar who never picks a lock. He collects keys dropped elsewhere and walks down the street trying every door.

It works because people reuse passwords. Analyzing 1.7 billion exposed credentials, SpyCloud found that 64% of users caught in two or more breaches were reusing similar passwords across accounts – the behavior that makes this attack viable at scale.

What Actually Protects Your Account

Because the 2022 incident started with passwords leaked elsewhere, the defenses that matter are account-level, not connection-level.

  • Use a unique password for PayPal. A password manager makes this practical. If the password exists nowhere else, a leak somewhere else cannot be reused against you.
  • Turn on two-factor authentication. 2FA would have blocked these credential-stuffing attempts outright, since a stolen password alone is no longer enough.
  • Know what a VPN does here. A VPN encrypts your traffic in transit – it scrambles data as it travels between your device and the internet. That protects you on public Wi-Fi and hides your IP address from sites and trackers. It does not stop someone who already has your password from logging in. Account security and connection security solve different problems, and you need both.

Looking Ahead: Future Outlook

The TIO case points to where risk is shifting. The weak link was not PayPal’s own platform but a company it had owned for a matter of months. PayPal was following its own security practices; TIO’s software supply chain was not held to the same standard. Expect more incidents to arrive through acquisitions, vendors and integrations rather than through the front door.

Source & Methodology

Figures come from PayPal’s own disclosures: its December 2017 statement on TIO Networks, reported by SecurityWeek, and its 2022 breach notification filed with state attorneys general, reported by Cybersecurity Dive. Because US notification laws vary by state, filed totals may understate global impact.