PayPal Reports Data Breach Information for Nearly 35,000 Accounts Worldwide

PayPal sent notifications to all the affected accounts asking them to change their passwords. PayPal said that there had been no breach in their systems.

One of the world’s largest online payment services platforms PayPal faced a major breach of data last month between December 6 and December 8, 2022. As per reports, the hackers got away with the sensitive information of 34,942 accounts.

PayPal noted that the data included the Name, address, personal tax identification numbers, social security number, and date of birth, of the compromised accounts. The company has already started sending notifications to all the compromised accounts while blaming a credential-stuffing attack for the breach.

In a recent notification sent this Wednesday, PayPal noted:

“On December 20, 2022, we confirmed that unauthorized parties were able to access your Paypal customer account using your login credentials”.

After learning about the new data breach on December 8, PayPal stopped the unauthorized access and started an investigation immediately. PayPal quickly reset the passwords of the affected accounts and “implemented enhanced security controls” that would require the affected accounts to set up a new password.

“We have no information suggesting that any of your personal information was misused due to this incident or that there are any unauthorized transactions on your account. There is also no evidence that your login credentials were obtained from any PayPal systems,” noted PayPal.

PayPal Claims No Breach In Systems

As the hackers gained unauthorized access to user accounts and their valid credentials, PayPal said that there was no breach in their systems. It noted that there’s no evidence that suggests that the users’ credentials were directly bought from them.

Instead, the hackers were able to access the accounts using credentials stuffing. This method involves trying several pairs of usernames and passwords sourced from data leaks, on various websites. Using bots, the list of credentials is inserted into their login portals of different services.

Users that use the same password for different online accounts are most-prone to becoming the victim of credential-stuffing attacks. As said, payments giant PayPal claims to have taken quick action in order to limit the hacker’s access to the platform and reset the passwords of the affected accounts. Besides, all the impacted users shall receive a two-year identity-monitoring service from Equifax for free.

PayPal also mentioned that the attackers didn’t manage to perform any transactions from the breached accounts. To prevent from becoming the victims of future hacks, users are advised to implement two-factor authentication (2FA) security features at their end.

Cybersecurity News, FinTech News, News, Technology News

Bhushan Akolkar

Bhushan is a FinTech enthusiast and holds a good flair in understanding financial markets. His interest in economics and finance draw his attention towards the new emerging Blockchain Technology and Cryptocurrency markets. He is continuously in a learning process and keeps himself motivated by sharing his acquired knowledge. In free time he reads thriller fictions novels and sometimes explore his culinary skills.

Read More
Bhushan Akolkar

Latest

Everything you need to know about Greek yogurt and how it can meet your nutrition needs

Recipes Two-ingredient cheesecake. Turkish-style pasta. Baked yogurt toast. Bagels....

Cook This: 3 recipes from Istanbul, including one of Turkey’s favourite breakfasts

Recipes Özlem Warren shines a light on the culinary...

Green Sauce Tofu and More Recipes We Made This Week

Recipes It’s no secret that Bon Appétit editors cook...

Newsletter

Don't miss

Everything you need to know about Greek yogurt and how it can meet your nutrition needs

Recipes Two-ingredient cheesecake. Turkish-style pasta. Baked yogurt toast. Bagels....

Cook This: 3 recipes from Istanbul, including one of Turkey’s favourite breakfasts

Recipes Özlem Warren shines a light on the culinary...

Green Sauce Tofu and More Recipes We Made This Week

Recipes It’s no secret that Bon Appétit editors cook...

Marshmallow Creme vs. Fluff: The Sweet and Sticky Showdown

Recipes Skip to main content Taste of Home Taste of Home Do...

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250