2026 PayPal — 104K credentials on dark web (infostealer)
Data compromised
Email addresses, passwords (from infected devices)
Technical writeup
In January 2026, ~104,000 PayPal email/password combinations were posted on a dark web forum by threat actor 'Lud.' Security researchers concluded PayPal was likely not directly breached; credentials appear to have come from infostealer malware harvested from infected user devices, not PayPal servers.
Root cause
Infostealer malware on user devices (not direct breach)