Payment methods leaked: what it means and what to do

Risk level: high. Can you change it: yes. Found in 3 breaches in this directory.

What this data is

The payment options saved to your account: the card brand and last digits, a PayPal or wallet email, direct debit bank details or a buy now pay later link. Some breaches include full card data, others only the type.

The risk on its own

How dangerous this is depends on what was stored. A label saying Visa or PayPal is minor, while full card or bank details allow real charges and direct debits. Read the breach notice carefully, because companies often describe both situations with the same words.

The risk combined with other data

With your name and email address, knowing your payment method lets scammers build fake payment pages for the exact provider you use. A PayPal email address becomes a phishing target, and bank details support unauthorised direct debits. Combined with an address, full card data supports purchases that pass basic fraud checks.

How criminals use it

  • A fake PayPal email is sent to the exact address linked to your account, saying a payment is on hold.
  • Full card details from the breach are used for online purchases at stores that do not require extra verification.
  • Bank account details on file are used to set up a direct debit you never approved.
  • A buy now pay later account linked to your email is taken over and used to order goods.

What to do now

  1. Ask the company in writing whether full card numbers, security codes or bank details were exposed, not just the payment type.
  2. If full card data leaked, call the number on the back of the card and ask for a replacement.
  3. Review direct debits in your online banking and cancel anything you do not recognise.
  4. Change the password on PayPal and any buy now pay later account, and turn on two-factor authentication for each.
  5. Delete saved payment methods from shopping accounts you rarely use.
  6. Turn on real time transaction alerts for every card and account linked to the breached service.

Frequently asked questions

Do I need a new card?

Yes if the full card number leaked or strange charges appear. If only the card type or last digits leaked, alerts and vigilance are usually enough.

Is PayPal safer than a card here?

The leak of a PayPal email does not expose your bank, but it makes you a target for PayPal phishing. Protect the PayPal login with a strong password and two-factor authentication.

Will my bank refund fraudulent charges?

Card issuers generally refund unauthorised charges reported promptly. Report them as soon as you see them.

Breaches that exposed this data

  • ClixSense: 2016-09-04, 2.4M accounts, Account balances, Dates of birth, Email addresses, Genders, IP addresses, Names
  • Udemy: 2026-04-24, 1.4M accounts, Email addresses, Employers, Job titles, Names, Payment methods, Phone numbers
  • Have Fun Teaching: 2021-08-15, 27K accounts, Browser user agent details, Email addresses, IP addresses, Names, Payment methods, Physical addresses

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.