DataBreachSearch.com
Investigation OpenMassachusetts AG filing · February 19, 2026

PayPal Reports Data Security Incident to Massachusetts Attorney General

PayPal, Inc. filed a report with the Massachusetts Attorney General on February 19, 2026, disclosing a data security incident. The company is actively investigating this event, which may have involved the exposure of personal information. Individuals should remain vigilant for potential risks.

State
Massachusetts
Reported
February 19, 2026

PayPal, Inc., a prominent global financial technology enterprise, filed a report concerning a data security incident with the Massachusetts Attorney General on February 19, 2026. This public filing indicates that the company is investigating a breach of its systems.

The official record states that the incident potentially involved the exposure of personal information. The specific categories of data affected were not detailed in the filing provided to the Attorney General's office.

This disclosure by PayPal, Inc. confirms that a security event has occurred, which can lead to various risks for affected individuals. The company has stated it is actively investigating the full nature and scope of this security incident.

Individuals who may be affected by this incident are advised to remain vigilant. It is generally recommended to closely monitor financial accounts and credit reports for any suspicious activity. Promptly report any unauthorized transactions or inquiries.

Consider changing passwords for online services, especially those linked to financial accounts, and use unique, strong passwords for each service. Additionally, be wary of unexpected communications, such as emails or text messages, that request personal details, and always verify the sender before clicking links or providing information.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases