Item 1A. Risk Factors
ITEM 1A: RISK FACTORS
We are subject to various risks and uncertainties, which could materially affect our business, results of operations, financial condition, future results, and the trading price of our common stock. You should read carefully the following information together with the information appearing in Part I, Item 1A, Risk Factors in our Annual Report on Form 10-K for the year ended December 31, 2025 as filed with the United States (“U.S.”) Securities and Exchange Commission (“SEC”) on February 3, 2026 (“2025 Form 10-K”) as updated by the information appearing in Part II, Item 1A, Risk Factors in our subsequent Quarterly Reports on Form 10-Q as filed with the SEC (“Forms 10-Q”). The following information supplements and, to the extent inconsistent, supersedes some of the information appearing in the Risk Factors section of our 2025 Form 10‑K and Forms 10-Q. These risk factors, as well as our condensed consolidated financial statements and notes thereto and the other information appearing in this report, should be reviewed carefully for important information regarding risks that affect us.
Cyberattacks and security vulnerabilities could result in serious harm to our reputation, business, and financial condition.
Techniques used to attempt to obtain unauthorized or illegal access to systems and information (including customers’ personal data), disable or degrade service, exploit vulnerabilities, or sabotage systems are continuously evolving. These attempts may not be recognized or detected until after they have been launched against a target. Unauthorized parties continuously attempt to gain access to our systems or facilities through various means, including through hacking into our systems or facilities or those of our customers, partners, or vendors, and attempting to fraudulently induce users of our systems (including customers, employees, and partner and vendor personnel) into disclosing user names, passwords, payment card information, multi-factor authentication application access or other sensitive information used to gain access to such systems or facilities. This information may, in turn, be used to access our customers’ confidential personal or proprietary information and financial instrument data that are stored on or accessible through our information technology (“IT”) systems and those of third parties with whom we partner. This information may also be used to execute fraudulent transactions or other activity. Numerous and evolving cybersecurity and related threats, including advanced and persisting cyberattacks, artificial intelligence (“AI”)-enabled threats, cyberextortion, distributed denial-of-service attacks, ransomware, spear phishing and social engineering schemes, the introduction of computer viruses or other malware, and the destruction of all or portions of our IT and infrastructure and those of third parties with whom we partner or that are part of our IT supply chain, are becoming increasingly sophisticated and complex, may be difficult to detect, and could compromise the confidentiality, availability, and integrity of the data in our systems, as well as the systems themselves, including through vulnerabilities that may be discovered and weaponized by new frontier AI models and autonomous agents.
We believe that hostile actors, who may comprise individuals, coordinated groups, sophisticated organizations, or nation-state supported entities, may target PayPal due to our name, brand recognition, types of data (including sensitive payments- and identity-related data) that customers provide to us, and the widespread adoption and use of our products and services. We have experienced from time to time, and may experience in the future, cybersecurity incidents, including breaches of our security measures, network breaches, and compromise of personally identifiable customer information due to human error, deception, malfeasance, insider threats, system errors, defects, vulnerabilities, or other issues. Any of the foregoing events may subject us to fines, penalties, regulatory or other enforcement actions, and adversely affect our business, reputation, or financial condition.
Any cybersecurity incidents, including cyberattacks or data security breaches affecting the IT or infrastructure of our customers, partners, or vendors (including data center and cloud computing providers) or of companies we acquire, could have similar negative effects.
2Q 2026 FORM 10-Q
64
Table of Contents
We have experienced, and may experience in the future, breaches involving customer information for which we have notified, and may notify, regulators, customers and other third parties. These or other cybersecurity breaches and other exploited security vulnerabilities have subjected us and could further subject us to significant costs and third-party liabilities, result in improper disclosure of data and violations of applicable privacy and other laws, require us to change our business practices, cause us to incur significant remediation costs, lead to loss of customer confidence in, or decreased use of, our products and services, damage our reputation and brands, divert the attention of management from the operation of our business, result in significant compensation or contractual penalties from us to our customers and their business partners as a result of losses to or claims by them, or expose us to litigation, regulatory investigations, and significant fines and penalties. Moreover, under payment card network rules and our contracts with our payment processors, if there is a breach of payment card information stored by us or our direct payment card processing vendors, we could be liable to the payment card issuing banks, including for their cost of issuing new cards and related expenses. While we maintain insurance to help offset the financial impact of these risks, our coverage may be insufficient to cover all our losses caused by security breaches and other damage to or unavailability of our systems.
Our business is subject to extensive government regulation and oversight. Our failure to comply with extensive, complex, overlapping, and frequently changing rules, regulations, and legal interpretations could materially harm our business.
Our business is subject to complex and changing laws, rules, regulations, policies, licensing schemes, and legal interpretations in the markets where (and relating to the industries and merchants to which) we offer services directly or through partners, including, but not limited to, those governing: banking, credit, deposit taking, cross-border and domestic money transmission, prepaid access, foreign currency exchange, privacy, data protection, data governance, cybersecurity, banking secrecy, digital payments, cryptocurrency, payment services (including payment processing and settlement services), lending, fraud detection, consumer protection, antitrust and competition, economic and trade sanctions, anti-money laundering, and counter-terrorist financing.
Regulators and legislators globally continue to establish, evolve, and increase their regulatory authority, oversight, and enforcement, and it may be difficult to predict how these may be applied to our business and the way we conduct our operations. As we introduce new products and services and expand into new markets and support new industries and merchants, including through acquisitions, we expect to become subject to additional regulations, restrictions, and licensing requirements. As we expand and localize our international activities, we expect that our obligations in the markets in which we operate will continue to increase. In addition, because we facilitate sales of goods and provide services to customers worldwide, one or more jurisdictions may claim that we or our customers are required to comply with their laws and regulations, which may impose different, more specific, and/or conflicting obligations on us, as well as broader liability.
We may not be able to respond quickly or effectively to regulatory, legislative, and other developments, and any failure or perceived failure to comply with existing or new laws, regulations, or orders of any government authority (including changes to or expansion of their interpretation) may result in audits, inquiries, investigations, whistleblower complaints, and adverse media coverage; subject us to significant fines, penalties, monetary damages, injunctive relief, criminal and civil lawsuits, forfeiture of significant assets, and enforcement actions in one or more jurisdictions; result in additional compliance and licensure requirements; cause us to temporarily or permanently lose existing licenses or prevent or delay us from obtaining additional licenses that may be required for our business; increase regulatory scrutiny of our business; divert management’s time and attention from our business; restrict our operations; lead to increased friction for customers; lead to loss of banking and other commercial partner relationships; force us to make changes to our business practices, products, or operations; require us to engage in remediation activities; or delay planned transactions, product launches, or improvements. Any of the foregoing could, individually or in the aggregate, harm our reputation, damage our brands and business, and adversely affect our results of operations and financial condition. The complexity of U.S. federal and state and international regulatory and enforcement regimes, coupled with the global scope of our operations and the evolving global regulatory environment, could result in a single event prompting a large number of overlapping investigations and legal and regulatory proceedings by multiple government authorities in different jurisdictions. While we have implemented policies and procedures designed to help ensure compliance with applicable laws and regulations, there can be no assurance that our employees, contractors, and agents will not violate such laws and regulations.
2Q 2026 FORM 10-Q
65
Table of Contents
Cryptocurrency Regulation and Related Risks
Our customer cryptocurrency offerings may subject us to additional regulations, licensing requirements, or other obligations or liabilities. Within the U.S., we are regulated by the New York State Department of Financial Services as a virtual currency business, which does not permit us to engage in securities brokerage or dealing activities. Additionally, we are a digital asset service provider under the Guiding and Establishing National Innovation for U.S. Stablecoins Act of 2025 (the “GENIUS Act”), which subjects us to obligations relating to our cryptocurrency business and may affect the competitive landscape for payment stablecoins. The regulatory status of particular cryptocurrencies is unclear under existing law. The evolving legislative and regulatory landscapes with respect to cryptocurrency in addition to stablecoins may subject us to additional licensing and regulatory obligations or to inquiries or investigations from various regulators and governmental authorities, and require us to change, restrict or discontinue product offerings in certain markets, implement additional and potentially costly controls, or take other actions.
We have partnered commercially with a third-party issuer (the “PYUSD Issuer”) that launched a U.S. dollar-denominated stablecoin, PayPal USD (“PYUSD”), which is available to PayPal customers and Venmo customers in certain markets. These PayPal and Venmo customers may, if provisioned for external transfers and subject to our sanctions and anti-money laundering controls, send PYUSD to external wallets not controlled by PayPal. The PYUSD Issuer may also allow institutional users to directly purchase PYUSD from the PYUSD Issuer (as per the PYUSD Issuer’s stablecoin terms and conditions). The regulatory treatment of stablecoins is evolving and has drawn significant attention from legislative and regulatory bodies around the world. The GENIUS Act provides a regulatory framework that is in the process of being implemented. While PYUSD is designed to comply with this U.S. framework, there remain uncertainties on how ongoing changes to international laws and regulations will apply to stablecoins in practice, and we and the PYUSD Issuer may face substantial costs and risks to operationalize and comply with any additional or changed requirements. If we or the PYUSD Issuer fail to comply with regulations, requirements, prohibitions or other obligations applicable to us, or make operational errors, we could face regulatory or other enforcement actions, potential fines, penalties, disruption to business or product availability, and other consequences. In addition, we could face reputational harm through our relationship with the PYUSD Issuer if the PYUSD Issuer were to face regulatory scrutiny or make operational errors or if PYUSD is alleged to be used for transactions in connection with illicit or illegal activities.
We hold our customers’ cryptocurrency assets through one or more third-party custodians. Financial and third-party risks related to our customer cryptocurrency offerings, such as inappropriate access to, theft, or destruction of cryptocurrency assets held by our custodians, insufficient insurance coverage by a custodian to fully reimburse us for such losses, a custodian’s failure to maintain effective controls over the custody and settlement services provided to us, a custodian’s inability to purchase or liquidate cryptocurrency holdings, the failure of the PYUSD Issuer to maintain sufficient reserve assets backing PYUSD, and defaults on financial or performance obligations by a custodian, banks with which the PYUSD Issuer maintains reserve assets or counterparty financial institutions, could expose us and our customers to loss and significantly harm our business, financial condition, and reputation.
We have selected custodian partners and the PYUSD Issuer, and may in the future select additional custodian partners and stablecoin issuing entities subject to regulatory oversight, capital requirements, maintenance of audit and compliance industry certifications, and cybersecurity procedures and policies. Any operational disruptions at any such custodian or issuer, or such custodians’ or issuer’s failure to safeguard cryptocurrency holdings (or reserve assets), could result in losses of customer assets, expose us to customer claims, reduce consumer confidence, harm our reputation, and materially impact our cryptocurrency product offerings and our operating results.
Custodial arrangements to safeguard cryptocurrency assets involve unique risks and uncertainties in the event of a custodian’s bankruptcy. While other types of assets and some custodied cryptocurrencies have been deemed not to be part of the custodian’s bankruptcy estate under various regulatory regimes, bankruptcy courts have not yet definitively determined the appropriate treatment of custodial holdings of digital assets in a bankruptcy proceeding. In the event of a custodian’s bankruptcy, the lack of precedent and the highly fact-dependent nature of the determination could delay or preclude the return of custodied cryptocurrency assets to us or to our customers. Although we contractually require our custodians to segregate our customer assets and not commingle them with proprietary or other assets, we cannot assure that these contractual obligations, even if duly observed by a custodian, will be effective in preventing such assets from being treated as part of the custodian’s estate under bankruptcy or other insolvency law. In that event, our claim on behalf of such customers against a custodian’s estate for our customers’ cryptocurrency assets could be treated as a general unsecured claim against the custodian, in which case our customers could seek to hold us liable for any resulting losses.
2Q 2026 FORM 10-Q
66
Table of Contents
We are regularly subject to general litigation, regulatory scrutiny, and government inquiries.
We are regularly subject to claims, individual and class action lawsuits, arbitration proceedings, government and regulatory investigations, inquiries, actions or requests, and other proceedings alleging violations of laws, rules, and regulations with respect to competition, antitrust, intellectual property, privacy, data protection, information security, anti-money laundering, counter-terrorist financing, sanctions, anti-bribery, anti-corruption, consumer protection (including unfair, deceptive, or abusive acts or practices), the terms of our customer agreements, fraud, accessibility, securities, tax, labor and employment, commercial disputes, services, charitable fundraising, contract disputes, escheatment of unclaimed or abandoned property, product liability, use of our services for illegal purposes, the matters described in “Note 13—Commitments and Contingencies—Litigation and Regulatory Matters—General Matters” to our condensed consolidated financial statements, and other matters. We expect that the number and significance of these disputes and inquiries will continue to increase as our products, services, and business expand in complexity, scale, scope, and geographic reach, including through acquisitions of businesses and technology, and as a result of expanded enforcement of certain existing laws and regulations by federal, state and local agencies in the U.S. and internationally. For example, there continues to be enforcement activity in connection with federal and state consumer protection laws, including suits which seek civil penalties. Investigations, changes in, or expanded enforcement of federal, state or local laws and regulations, and legal and regulatory proceedings are inherently uncertain, expensive and disruptive to our operations, and could result in substantial judgments, fines, penalties or settlements, substantial diversion of management’s time and effort, negative publicity, reputational harm, criminal sanctions, or orders that prevent or limit us from offering certain products or services; require us to change our business practices or customer agreement terms in ways that may increase costs or reduce revenues, develop non-infringing or otherwise altered products or technologies, or pay substantial royalty or licensing fees; or delay or preclude planned transactions or product launches or improvements. Determining legal reserves or possible losses from such matters involves significant estimates and judgments and may not reflect the full range of uncertainties and unpredictable outcomes. We may be exposed to losses in excess of the amount recorded, and such amounts could be material. If our estimates and assumptions change or prove to have been incorrect, this could have a material adverse effect on our business, financial position, results of operations, or cash flows.
Failure to deal effectively with fraud, abusive behaviors, bad transactions, and negative customer experiences may increase our loss rate and could severely diminish merchant and consumer confidence in and use of our services and negatively impact our business.
We expect that third parties will continue to attempt to abuse access to and misuse our payments services to commit fraud by, among other things, creating fictitious accounts using stolen or synthetic identities or personal information, taking over customer accounts or creating fraudulent accounts, making transactions with stolen financial instruments, abusing or misusing our services for financial gain, or fraudulently inducing users of our products and services into engaging in fraudulent transactions, any of which could be enhanced or facilitated by AI. Due to the nature of our digital payments services, third parties may seek to engage in abusive schemes or fraud attacks that are often difficult to detect and may be deployed at a scale that would otherwise not be possible in physical transactions. Measures to detect and reduce the risk of fraud and abusive behavior are complex, require continuous improvement, and may not be effective in detecting and preventing fraud, particularly new and continually evolving forms of fraud or in connection with new or expanded product offerings. If these measures are not effective, our business could be negatively impacted. We also incur substantial losses from erroneous transactions and situations where linked accounts designated by customers to fund PayPal transactions have insufficient funds or are otherwise unavailable to fund the payments, or the payment is initiated to an unintended recipient in error. Numerous and evolving fraud schemes and misuse of our payments services could subject us to significant costs and liabilities, require us to change our business practices, cause us to incur significant remediation costs, lead to loss of customer confidence in, or decreased use of, our products and services, damage our reputation and brands, divert the attention of management from the operation of our business, and result in significant compensation or contractual penalties from us to our customers and their business partners as a result of losses or claims. While we actively seek to recover transaction losses where possible, such recoveries may be insufficient to compensate us for such losses.
Our purchase and seller protection programs (“protection programs”) are intended to reduce the likelihood of losses for consumers and merchants from unauthorized and fraudulent transactions. Our purchase protection program also protects eligible transactions where consumers do not receive the item ordered or receive an item that is significantly different from its description. We incur substantial losses from our protection programs as a result of disputes filed by our customers. While we may seek to recover losses from our protection programs from the merchant, we ultimately may not be able to fully recover such losses.
2Q 2026 FORM 10-Q
67
Table of Contents
In addition, consumers who pay through PayPal or Venmo may have reimbursement rights from their payment card issuer, which in turn will seek recovery from us. If losses incurred by us related to payment card transactions become excessive, we could lose the ability to accept payment cards for payment, which would negatively impact our business. Regulators and card networks may also adapt error resolution and chargeback requirements to account for evolving forms of fraud, which could increase PayPal’s exposure to fraud losses and impact the scope of coverage of our protection programs. Increases in our loss rate, including as a result of changes to the scope of transactions covered by our protection programs, could negatively impact our business and results of operations.
Failure to effectively monitor and evaluate the financial condition of our merchants may expose PayPal to losses. In the event of the bankruptcy, insolvency, business failure, or other business interruption of a merchant that sells goods or services in advance of the date of their delivery or use (e.g., airline, cruise, or concert tickets, custom-made goods, and subscriptions), we could be liable to the buyers of such goods or services, including through our purchase protection program or through chargebacks on payment cards used by customers to fund their purchase. Allowances for transaction losses that we have established may be insufficient to cover incurred losses.
Global and regional economic conditions could harm our business.
Adverse global and regional economic conditions—including political unrest and turmoil, geopolitical tensions, armed conflicts, or military escalation—affecting the banking system or financial markets, including, but not limited to, tightening in the credit markets; extreme volatility or distress in the financial markets (including the fixed income, credit, currency, equity, and commodity markets); unemployment; consumer debt levels; recessionary or inflationary pressures; supply chain issues; reduced economic activity, consumer confidence, or discretionary spending; government fiscal, monetary, and tax policies; U.S. and international trade relationships, agreements, and treaties; changes in or new tariffs and restrictive actions or threats of such actions (including an escalation of trade tensions between the U.S. and its trading partners); the inability of a government to enact a budget in a fiscal year; government shutdowns or austerity measures; and other events or adverse geopolitical conditions, financial news, or macroeconomic developments could have a material adverse impact on the demand for our products and services, including a reduction in the volume and size of transactions on our platform. In particular, tariffs and reciprocal trade measures enacted or threatened to be enacted by the U.S. and other countries have led to increased volatility and uncertainty in certain parts of the global economy. We cannot predict the timing, strength or duration of any economic volatility, slowdown, instability or recovery, whether in the U.S. or globally, or within any particular industry. These conditions could have a material adverse impact on the demand for our products and services which could adversely affect our results of operations. Additionally, any inability to access the capital markets when needed due to volatility or illiquidity in the markets, liquidity needs due to unanticipated reductions in customer balances, or increased regulatory liquidity and capital requirements may strain our liquidity position. Such conditions may also expose us to fluctuations in foreign exchange rates or interest rates that could materially and adversely affect our financial results.
2Q 2026 FORM 10-Q
68
Table of Contents
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.