Blog
New York fines PayPal $2 million for shoddy security practices
Summary: The New York State Department of Financial Services (DFS) imposed a $2 million civil penalty on PayPal in January 2025 after investigating a 2022 incident that exposed unmasked customer information in Form 1099-K documents. The regulator linked the incident to weaknesses in change management, staff training and access controls.
What happened
PayPal changed data-collection flows in 2022 so more customers could access Form 1099-K tax documents. DFS said the updated forms went live on October 18, 2022 with names, dates of birth and full Social Security numbers left unmasked. In December, PayPal detected online instructions describing how to view the data and then observed automated credential-stuffing attempts against customer accounts.
Control failures identified by the regulator
According to the DFS consent order, the engineering team misclassified the change as a platform migration. As a result, PayPal’s required risk-and-control review was not performed, and the release proceeded without the expected risk assessment, penetration test or vulnerability scan and without formal launch approval. DFS also found that multi-factor authentication was optional for the affected customer accounts at the time.
Response and remediation
DFS said PayPal masked the exposed information, added CAPTCHA and rate limiting, and forced password resets for affected accounts. The company also clarified its change-management policies, trained the responsible engineering team, improved controls that associate production releases with required approvals and introduced mandatory multi-factor authentication for U.S. customer logins.
Security takeaway
The case shows that written security policies are not sufficient if release classification, testing and approval controls can be bypassed. Changes involving sensitive customer data should trigger mandatory security review, automated checks and production monitoring. Strong authentication and abuse controls can reduce the impact when reused credentials are tested at scale.
Original sources: New York State Department of Financial Services — PayPal consent order; SC Media — original report.
Independently summarized and reviewed by CNB Telecom. Last reviewed: September 7, 2026.