العربية

Palestine” is missing from the list..
and its people’s faces are on file in Tel Aviv

An investigation into how PayPal’s new updates discriminate against Palestinians, and how its partnership with an Israeli firm raises concerns over the security of their data

Every time a Palestinian user uploads a photograph of their passport or identity card to PayPal, or takes a picture of their face to prove who they are, they may assume that this data will not leave the company’s technical systems beyond what is required to complete the verification. But with new updates taking effect in June 2026, the matter goes well beyond security procedures or regulatory requirements.

These changes, announced by PayPal and already being applied to Palestinian users in the occupied territories and the Gaza Strip, open the door to far more sensitive questions: who processes this data? Who has the right to access it? And what changed once PayPal’s operations in the occupied Palestinian territories moved to a new Israeli legal entity?

The questions this Arabic Post investigation opens
  • Who processes this data?
  • And who has the right to access it?
  • And what changed once PayPal’s operations in the occupied Palestinian territories moved to a new Israeli legal entity?
  • How do the new updates amount to discriminatory measures against Palestinians, and raise concerns over the security of their personal information?

The changes the company has begun to apply impose stricter verification procedures on Palestinians, including biometric identity verification — at a time when PayPal’s own documents reveal that part of this process is carried out by an Israeli digital-verification company led by former officers of Israeli military intelligence units, which handles identity documents and personal photographs within the company’s compliance and anti-fraud system.

This investigation traces the threads connecting PayPal to Israeli companies working in cybersecurity and biometric verification, and examines whether the effects of the new updates are confined to Palestinians in the occupied territories — or whether they also raise broader questions about the privacy of millions of Arab users: how their sensitive data is collected and processed, and who stands behind a technical system that has become a compulsory gateway to the digital economy.

Methodology

This investigation is based on an analysis of PayPal’s documents and policies and of regulatory disclosures relating to its activities in Israel and the occupied Palestinian territories; on tracing corporate records and acquisitions, privacy documents and data-processing agreements; and on a review of the profiles of executives and employees on professional platforms, alongside specialist reporting on cybersecurity and data protection.

Lines of inquiry

From biometric verification to the absence of "Palestine": how did PayPal’s new updates expose digital racial discrimination?

Investigation: PayPal’s new updates reveal a fresh face of digital racial discrimination against Palestinians.

PayPal’s updates reveal an Israeli network behind identity verification and raise fears of deepening discrimination against Palestinians.

Inside PayPal: how does discrimination against Palestinians intersect with a network of companies led by former Israeli intelligence officials?

The legal transfer

What changed in June 2026?

From a Singaporean entity to an Israeli subsidiary answering directly to the Israel Securities Authority.

In early June 2026, PayPal began a new phase in the restructuring of its operations in the occupied Palestinian territories, paving the way to transfer the running of its services from the Singaporean entity PayPal Pte. Ltd to a newly created subsidiary named PayPal Israel Payment Services Ltd, after applying for a payment service provider licence (PSP Licence) from the Israel Securities Authority.

The entity operating the service in the occupied Palestinian territories
Until May 2026
PayPal Pte. Ltd
An entity registered in Singapore, running the service from outside the region.
From June 2026
PayPal Israel Payment Services Ltd
A new subsidiary, which has applied for a payment service provider (PSP) licence.
PSP
Licensing and supervisory authority: the Israel Securities Authority — under the transfer, operations come directly under Israeli law and regulatory oversight, including the November 2024 instructions requiring licensed payment firms to tighten customer identity verification (KYC).

Under this transfer, PayPal’s operations in the region come directly under Israeli law and regulatory oversight, including the instructions issued by the Israel Securities Authority in November 2024, which require licensed payment companies to apply stricter customer identity verification procedures (KYC).

These procedures include electronic identity verification using official documents and, in some cases, biometric verification by matching a photograph of the face against identity documents.

Although the company has presented these changes as part of regulatory compliance requirements, they may raise digital-rights concerns — not only because verification requirements have been tightened on Palestinians, but also because they deepen PayPal’s ties to the Israeli financial system at a time when the company faces sustained criticism over its policies towards Palestinians in the occupied territories.

But the legal change is only part of the story. As identity verification tightens, another and more consequential question comes into view: who actually processes the personal documents and biometric data that users upload to PayPal? That question leads to a network of digital-verification companies, headed by an Israeli firm that has become a principal partner in the process.

The data

What does PayPal know about its users?

A range that goes beyond what a payment requires — ending at an identity document and a photograph of your face.

Before turning to the companies that carry out identity verification, PayPal’s own documents and privacy policies reveal that it collects a wide range of data on its users, going beyond the basic information needed to complete payments.

Alongside name, address, email, phone numbers, banking details and transaction history, the platform collects technical data about how the service is used — device type, operating system, internet protocol (IP) address and approximate geographic location — as well as information tied to user behaviour inside the platform and, in some cases, the websites or applications that referred the user to PayPal.

The layers of data the platform collects
Identity and transaction data
Base layer
NameAddressEmailPhone numbersBanking detailsTransaction history
Technical and behavioural data
Collected during use
Device typeOperating systemIP addressApproximate locationIn-platform behaviourReferring site or app
Identity documents and biometric data
On suspicion, or under KYC
PassportIdentity cardDriving licenceSelfie photographShort video for biometric verification
The third layer is the heart of this investigation: data its owner cannot change or replace if it is ever breached.

The data above may look much like what many other applications request. But with identity documents and biometric data, the platform gives their owner no way to change, replace or delete them — and the party administering this process on PayPal’s behalf raises questions and concerns about the security of personal information and about who gains access to it, as will be set out below.

When fraud risk is suspected, or when "Know Your Customer" (KYC) requirements are applied, the company asks users to upload official identity documents — a passport, identity card or driving licence — along with a personal photograph or a short video for biometric verification that the face matches the official document.

The privacy policy states that this data is used for regulatory compliance, anti-money-laundering, counter-terrorist-financing and fraud prevention — requirements imposed by regulators in the various countries where the company operates.

These operations, however, are not carried out entirely inside PayPal. The company relies on external service providers specialising in digital identity verification, as its own data-processing documents acknowledge. Among those providers, one Israeli company has come to play a pivotal role in the biometric verification PayPal carries out.

The provider

The company that verifies your identity

Au10tix Limited — an Israeli firm that reads your passport and matches your face against it.

PayPal’s published data-processing documents reveal that the company relies on Au10tix Limited to carry out part of its digital identity verification. Au10tix is an Israeli company specialising in biometric verification, data extraction from official documents, and the detection of forgery and fraud.

Its services include reading data automatically from passports, identity cards and driving licences, then matching the personal photograph or "selfie" against the official document using facial-recognition technology and liveness detection — a step intended to confirm that the person being verified is physically present, rather than using a still image or a forged identity.

How your face is matched against your document
Official document Live selfie Match + liveness check
→ Scroll horizontally to see the full diagram
IllustrationThe document’s data is read automatically, the live image is matched against the document photograph, and the system checks that the person is physically present rather than a still image — the steps that pass through the external provider’s systems.
The identity-verification pipeline — from upload to decision
01
Document upload
Passport, identity card or driving licence, plus a selfie or a short video.
The user
02
Automated data reading
Data extracted straight from the official document, with no manual entry.
Au10tix
03
Face matching
The selfie compared against the official document using facial recognition.
Au10tix
04
Liveness detection
Confirming the person is physically present — not a still image or a forged identity.
Au10tix
05
Compliance decision
The result folded into compliance, risk-management and anti-fraud procedures.
PayPal
According to PayPal’s data-processing documents, the user’s documents and photograph pass through the external provider’s systems to complete steps 02 to 04.
Who holds a copy of your document at each step
The user Uploads document and photo The platform Requests verification Au10tix An Israeli company Verification provider Processes document and face
→ Scroll horizontally to see the full diagram
IllustrationThe third link is where the question lies: the document and the photograph leave the platform for a third party specialising in digital verification.

According to PayPal’s documents, these services are used within compliance and risk-management procedures — meaning that a user asked to verify their identity may have their data and documents pass through Au10tix’s systems to complete the process.

What draws privacy researchers to this arrangement is not only the nature of the technology, but the identity of the company itself, the background of its founders and senior officials, and its record in handling sensitive data — factors that have led a number of researchers to question the level of governance and oversight applied to the biometric data processed through this system.

According to research carried out by Arabic Post, Au10tix is not merely a start-up in digital verification: its roots extend into a network of Israeli security companies, and it is led by former officials, some of them linked to Israeli military intelligence units — which opens the door to broader questions about the nature of this system and the relationships behind it.

Intelligence roots and a security network

From an airport-security firm founded by the father, to a global biometric-verification provider led by the son.

Au10tix matters not only as a technical provider of identity-verification services, but because of who founded it and the corporate network it emerged from.

The company was founded by Ron Atzmon, whose published professional profile refers to prior military service, while specialist media reports have linked his name to Unit 8200 of Israeli military intelligence — the unit known for developing electronic-intelligence and cyber-warfare capabilities, and from which a large number of Israel’s technology and cybersecurity founders have emerged.

The professional profile of Au10tix founder Ron Atzmon
Professional profile of Ron Atzmon showing his founding of Au10tix and prior military service
A professional profile identifying Ron Atzmon as founder and active chairman of AU10TIX, listing in his military record the rank of platoon sergeant in the Israeli Navy between November 1992 and October 1995. Beneath it, a note describes Au10tix as an Israeli authentication platform relied on by companies including LinkedIn, Uber, TikTok and X, refers to a data breach that leaked personal information, and states that the active chairman was a previous member of Unit 8200 and that his father is closely tied to the Likud party.

Tracing the company’s corporate record shows that Au10tix did not emerge in isolation from this environment. It is one of the companies that came out of the ICTS International group — a security firm founded by Menachem Atzmon, the father of Au10tix’s founder, in cooperation with former officials of Israel’s internal security service (Shin Bet) and former security officials of the Israeli airline El Al, with the aim of marketing Israeli security expertise in protecting airports and infrastructure around the world.

The corporate record — where the company came from
ICTS International
A security firm founded by Menachem Atzmon — father of Au10tix’s founder — to market Israeli security expertise in protecting airports and infrastructure worldwide.
Former officials of the internal security service (Shin Bet) Former security officials of El Al
Au10tix Limited
One of the companies that emerged from the group, founded by Ron Atzmon. His published professional profile refers to prior military service, and specialist media reports have linked his name to Unit 8200 of Israeli military intelligence.
Unit 8200 — electronic intelligence and cyber warfare Biometric verification and forgery detection

Over the past two decades Au10tix has moved from verifying travel documents to becoming one of the world’s leading biometric-verification providers, with a client list that includes major technology and digital-services companies — among them X (formerly Twitter), TikTok, Uber, Coinbase and LinkedIn, alongside PayPal.

Who relies on the same provider
X (formerly Twitter) TikTok Uber Coinbase LinkedIn PayPal

This record is not in itself evidence of data misuse, but it explains part of the attention paid to the company’s role in processing biometric data — particularly given its ties to an Israeli security and intelligence environment, and the reliance of major financial platforms on it to verify the identities of millions of users.

The security record

Breaches, and questions about where the data ends up

From malware on an operations manager’s machine, to a two-million-dollar settlement in New York.

Alongside the company’s corporate background, its security record stands out as one of the main reasons for the controversy surrounding its role in running identity verification.

A sequence of security incidents
December 2022
Some 35,000 PayPal accounts breached
Using login credentials leaked from other services — exposing names, addresses, social security numbers and dates of birth.
December 2022 — June 2024
Au10tix breached through malware
An operations manager’s machine was infected, leaking employee credentials via Telegram and opening access to systems holding identity documents, passport images and biometric data.
January 2025
A two-million-dollar settlement with New York’s financial regulator
After the company was accused of failing to meet certain cybersecurity requirements.
July — December 2025
A coding error in PayPal Working Capital
Exposed some customers’ data — names, phone numbers, dates of birth and social security numbers — for close to six months.
February 2026
The breach notice and the MintPress News report
The company disclosed the incident, coinciding with a report carrying accounts from users who said their real names began appearing in searches from inside Israel after they uploaded their documents.

Between December 2022 and June 2024, Au10tix suffered a cyber breach caused by malware infecting the machine of one of its operations managers, leaking employee credentials via Telegram.

Au10tix employee credentials leaked via Telegram
Excerpt from a report on the leak of Au10tix employee credentials
An excerpt documenting that the credentials appear to have been scooped up by malware in December 2022 and placed on a Telegram channel in March 2023, according to timestamps and messages obtained by 404 Media, which found passwords and authentication tokens linked to someone whose role is listed on LinkedIn as a Network Operations Center Manager at AU10TIX.

According to investigations disclosed later, the breach opened access to systems holding identity documents, passport images and users’ biometric data. Specialist reports also indicated that some of the data remained at risk even after the company announced that the incident had been contained.

In February 2026, a report published by MintPress News raised further questions after it carried accounts from users on X who said their real names had begun appearing in searches from inside Israel shortly after they uploaded their documents to Au10tix’s system to verify their accounts.

User accounts: our names were searched from inside Israel
Posts by users on X saying their full names were searched from inside Israel
Posts on X whose authors say their full legal names were searched from inside Israel within a matter of days, accompanied by screenshots from a trends tool showing a sudden spike in searches for the name inside Israel over the previous seven days.

While these observations are not conclusive evidence of a leak from inside the company, they prompted information-security researchers to call for greater transparency about how biometric verification data is managed.

Nor is the record of security incidents confined to Au10tix. PayPal itself has faced a number of incidents in recent years relating to the protection of user data.

In December 2022, the company suffered a cyberattack that breached some 35,000 accounts using login credentials leaked from other services, exposing personal information including names, addresses, social security numbers and dates of birth.

Lawsuit — the breach of 35,000 customers
Headline: PayPal faces lawsuit over December data breach involving 35,000 customers
A lawsuit against PayPal over the December 2022 breach that affected some 35,000 customers.
The market in leaked login data
A forum listing offering a credential database attributed to PayPal accounts
A listing on a specialist forum offering a large credential database for sale, attributed to PayPal accounts — an indication of the scale of the market in leaked login data.

The case ended in January 2025 with a settlement with the New York State Department of Financial Services, under which PayPal paid two million dollars after being accused of failing to meet certain cybersecurity requirements.

New York’s financial regulator — a two-million-dollar settlement
Statement by New York's Department of Financial Services on a two-million-dollar settlement with PayPal
A statement issued on 23 January 2025 announcing the settlement, following an investigation which found that the company had failed to use qualified personnel to manage key cybersecurity functions and to provide adequate training, leading to the exposure of sensitive customer information including social security numbers.

In February 2026 the company also disclosed a separate incident caused by a coding error in its PayPal Working Capital service, which exposed some customers’ data — including names, phone numbers, dates of birth and social security numbers — for close to six months.

Official data-breach notice — PayPal Working Capital
Official PayPal data breach notice dated 10 February 2026
A notice sent by PayPal on 10 February 2026 explaining that an error in its loan application exposed a number of customers’ personal data to unauthorised individuals between 1 July 2025 and 13 December 2025, covering name, email address, phone number, business address, social security number and date of birth.

However different these incidents may be in nature, their recurrence — together with PayPal’s reliance on outside companies to process identity verification — brings back a fundamental question: how far can global financial platforms guarantee the security of the biometric data that has become an essential part of their services?

"Digital racial discrimination" against Palestinians

There is no option called "Palestine" in the country list — while the service operates inside the settlements.

The controversy around PayPal is not confined to how it collects data or to the companies that carry out identity verification. It extends to the nature of the service the company provides in the occupied Palestinian territories — a service that has for years drawn criticism from human-rights organisations and Western politicians who accuse it of discriminating between Palestinians and Israeli settlers.

When opening a new account, the platform offers no "Palestine" option in its list of countries — forcing Palestinians living in East Jerusalem, or those holding Israeli documents, to register their accounts as residents of "Israel" if they want access to certain services.

By contrast, PayPal makes its services available to Israeli settlers living in West Bank settlements, even though those settlements are considered illegal under international law.

The country list when opening a new account
Country / Region
Egypt
Cyprus
Israel
Italy
Jordan
Palestine Not listed
IllustrationNo "Palestine" option appears, so residents of East Jerusalem or holders of Israeli documents are forced to register as residents of "Israel". The list here is illustrative only and is not a screenshot.
The same land — two different services
The Palestinian user
  • No "Palestine" option appears in the country list when opening a new account.
  • Residents of East Jerusalem or holders of Israeli documents are forced to register as residents of "Israel" to access certain services.
  • The company’s justification: the operating environment in the Palestinian territories is "high risk".
  • Under the new updates: verification requirements that not all users can meet, or for which they lack the documents.
The Israeli settler
  • The service is available to residents of West Bank settlements.
  • Even though those settlements are considered illegal under international law.
  • Full access to the digital economy from within the same territory.
  • Eleven members of Congress said this disparity raises concerns of discrimination and violation of economic rights.
Venmo halts payments referring to PalestineVenmo
Report on Venmo stalling payments that mention Palestine
A report that Venmo, owned by PayPal, halted some payments referring to Palestine, after a number of its users said the app had stalled transfers to the "Emergency Palestinian Relief Fund".

The policy has drawn criticism inside the United States itself: eleven members of Congress sent a letter to PayPal’s management arguing that the company’s continued provision of services to Israeli settlers, while denying Palestinians equal access to the digital economy, raises concerns of discrimination and the violation of economic rights.

The company has offered no detailed explanation for the policy, noting on previous occasions only that the operating environment in the Palestinian territories is "high risk" — a justification that has not convinced its critics, who point out that PayPal continues to operate in markets and countries experiencing armed conflict or more complex security conditions.

PayPal’s partnership with the Anti-Defamation League (ADL)
Press release on PayPal's partnership with the Anti-Defamation League
A press release issued on 26 July 2021 announcing a partnership between PayPal and the Anti-Defamation League (ADL) to analyse what they described as attempts to exploit financial systems, with the findings of the research initiative to be shared with the financial sector, policymakers and law enforcement.

As the new identity-verification updates take effect, rights advocates fear these procedures will become a further obstacle for Palestinians, if continued use of the service is tied to verification requirements that not all users can satisfy, or that demand documents many of them do not hold.

The wider reach

Do the concerns extend to Arab users?

The questions do not stop at the geographic borders of the occupied territories.

Although the recent regulatory updates target PayPal’s operations in the occupied Palestinian territories, the questions this investigation raises do not stop at that region’s geographic borders.

PayPal’s policies for collecting personal and financial data, and the identity-verification procedures it applies, are used to varying degrees on its users worldwide — including in the Arab countries where the company operates.

When a user is asked to verify their identity, the process may involve uploading official documents and a photograph of their face — data that, according to the company’s own documents, may be processed by external providers specialising in digital verification, among them the Israeli company Au10tix.

The path of an identity document — from the user to where?
The Arab user
Uploads an official document and a photograph of their face in response to a verification request.
The PayPal platform
Data-collection and verification policies apply to varying degrees to users worldwide.
External verification provider
Among them the Israeli company Au10tix, according to PayPal’s data-processing documents.
Data governance
Who processes it? And what legal safeguards govern its use and protection?
This does not mean all user data is transferred to an Israeli company, nor that it automatically becomes available to any government body — but it explains why privacy experts pause at this particular link in the chain.
Why biometric data is different
Password and bank card
If leaked, they can be changed or reissued.
Replaceable
Your face and identity document
Their owners can hardly change or replace them if they are ever breached.
Not replaceable

This does not mean that all PayPal users’ data is transferred to an Israeli company, or that such data automatically becomes available to any government body. But the platform’s reliance on an Israeli provider for part of its biometric verification raises, according to digital-privacy experts, questions about data governance, about who processes it, and about the legal safeguards governing its use and protection — particularly where biometric data and identity documents are concerned, which their owners can hardly change or replace if they are ever breached.

These concerns are growing as the world becomes more dependent on biometric verification in financial services. The debate is no longer confined to how effective these systems are at combating fraud; it now extends to sovereignty over sensitive data, transparency in choosing the companies that process it, and the oversight imposed on them.

In this context, the PayPal case raises a question that concerns not only Palestinians. It opens a wider debate about the future of digital privacy for millions of Arab users who rely on global financial platforms for their daily transactions — many of them without knowing how their data is processed, or which parties take part in that process.

The network

An Israeli network inside PayPal

Acquisitions, development centres and personnel — the connection runs deeper than a single service provider.

PayPal’s connection to Israel is not limited to its reliance on Au10tix for part of its identity verification. It extends to a wider network of companies, investments and personnel that have shaped the company’s technical infrastructure over recent years.

Since entering the Israeli market, PayPal has acquired a number of local companies specialising in cybersecurity and fraud prevention — among them FraudSciences in 2008, which formed the nucleus of the company’s anti-fraud centre in Israel, then CyActive, which specialised in predicting cyberattacks, before expanding its presence by acquiring Curv and Cymbio, which work in digital asset management and e-commerce.

Acquisitions inside the Israeli market
AcquirerPayPal
2008
FraudSciences
Formed the nucleus of the company’s anti-fraud centre in Israel.
Later
CyActive
Specialised in predicting cyberattacks.
Expanding presence
Curv
Digital asset management.
Expanding presence
Cymbio
E-commerce.
CyActive — acquired by PayPal, Be’er Sheva
Company profile of CyActive showing PayPal as acquirer and its base in Be'er Sheva
A company profile of CyActive, a predictive cybersecurity firm, showing PayPal as the acquiring party and its headquarters in Be’er Sheva in the southern district.
CyActive — funding and founders
CyActive funding rounds and its founders Shlomi Boutnaru and Liran Tancman
CyActive’s funding rounds and its key people: Shlomi Boutnaru (CTO and co-founder) and Liran Tancman (CEO and co-founder).

PayPal also employs at its Israeli centres a number of engineers and data specialists whose professional profiles reveal prior service in Israeli military intelligence units, foremost among them Unit 8200. This is common across the Israeli technology sector, but it takes on added sensitivity when the company in question is a global financial platform handling the financial and biometric data of millions of users.

Lead decision scientist — a record in military intelligence
Professional profile of a lead decision scientist at PayPal showing prior work in Israeli military intelligence
A professional profile of a Lead Decision Scientist at PayPal in Israel, showing in her employment record prior work as a research analyst in Israeli military intelligence between 2012 and 2014.
Decision scientist — the "Technological Intelligence Unit"
Professional profile of a decision scientist at PayPal showing prior work in the Technological Intelligence Unit
Another professional profile, of a Decision Scientist at PayPal, showing prior work as a data analyst in the Israeli army between 2008 and 2010, with a role description referring to analysing data collected by the "Technological Intelligence Unit" using business-intelligence software, focused on the networks and communications of people of interest in counter-terrorism.
Peter Thiel — from PayPal to Palantir
Peter Thiel, a PayPal co-founder, speaking in front of the Palantir logo
Peter Thiel, a co-founder of PayPal, speaking in front of the logo of the data-analytics company Palantir, which he later co-founded — an image that captures how the network of the platform’s founders extends into the data-analytics and security industry.

The presence of former members of these units, or the acquisition of Israeli companies, is not in itself evidence that user data has been misused. But it does reveal the scale of the institutional and technical ties PayPal has built inside the Israeli technology system — a network whose importance grows as the company moves to an Israeli legal entity and widens its reliance on digital verification technologies.

Right of reply

Arabic Post contacted both PayPal and Au10tix for comment on the findings of this investigation, and to ask about how user data is processed, what safeguards are in place to protect biometric data, and what role contracted companies play in these operations. No response had been received by the time of publication.