Breadcrumb

  • Home
  • PayPal's Databreach affects 34,942 users after fascinating form of attack.

Search form

Main navigation

  • Home

PayPal's Databreach affects 34,942 users after fascinating form of attack.

Friday, 20 January, 2023 - 06:33

It might not sound like a lot of people, given PayPal's large customer-base but it turns out to be a pretty big deal after all.

PayPal logo

PayPal has issued "data breach notifications" to at least 35,000 people whose account information has been illegally accessed. The technique for the attack is fascinating.

There are many, many data breaches ranging from a handful to several millions of personal records. The product of those breaches can be easily and cheaply bought. The fascinating part of the PayPal hack is that someone has obtained multiple datasets and then combined usernames and passwords looking for pairs that give access.

Of course, this technique has a name - "credential stuffing."

The attack took place between 6th and 8th December, 2022. PayPal identified it and took action to, as the company says, "mitigate" it. It's not clear if "mitigation" means "block." Initially, PayPal knew there was a breach but did not know exactly what it was. An urgent internal investigation concluded that there was no "insider" involvement and that the attack was by unknown third parties who had managed to create pairs of usernames and passwords that created valid credentials.

The records that the hackers accessed are important: account holders' full names, dates of birth, postal addresses, social security numbers and individual tax identification numbers

That, then, is essentially all that's needed to create a parallel identity in the USA.

PayPal did not say whether transaction data and payment card information was also affected but it does say that there were no attempts, successful or otherwise, to make any transactions within the subject accounts. PayPal changed the passwords of the affected accounts to prevent further access. This, of course, means that, if the new passwords are high-security passwords, it's unlikely that a further round of cross-matching between existing publicly available datasets will gain access.

PayPal is to provide each affected user with two years of identity monitoring services from Equifax at no charge.

It appears that none of the affected accounts belonged to users who had implemented two-factor authentication.

PayPal's notice is here: https://www.documentcloud.org/documents/23578067-paypal-notice?responsi…

December was a busy month for this type of hacker: Norton LifeLock also came under attack. See here: https://www.pleasebeinformed.com/publications/ChiefOfficersNetwork_com/…

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.