← PayPal

2026 PayPal — 104K credentials on dark web (infostealer)

2026 104.0K records affected Share on X

Data compromised

Email addresses, passwords (from infected devices)

Technical writeup

In January 2026, ~104,000 PayPal email/password combinations were posted on a dark web forum by threat actor 'Lud.' Security researchers concluded PayPal was likely not directly breached; credentials appear to have come from infostealer malware harvested from infected user devices, not PayPal servers.

Root cause

Infostealer malware on user devices (not direct breach)

References