PayPal's Databreach affects 34,942 users after fascinating form of attack.

PayPal has issued "data breach notifications" to at least 35,000 people whose account information has been illegally accessed. The technique for the attack is fascinating.
There are many, many data breaches ranging from a handful to several millions of personal records. The product of those breaches can be easily and cheaply bought. The fascinating part of the PayPal hack is that someone has obtained multiple datasets and then combined usernames and passwords looking for pairs that give access.
Of course, this technique has a name - "credential stuffing."
The attack took place between 6th and 8th December, 2022. PayPal identified it and took action to, as the company says, "mitigate" it. It's not clear if "mitigation" means "block." Initially, PayPal knew there was a breach but did not know exactly what it was. An urgent internal investigation concluded that there was no "insider" involvement and that the attack was by unknown third parties who had managed to create pairs of usernames and passwords that created valid credentials.
The records that the hackers accessed are important: account holders' full names, dates of birth, postal addresses, social security numbers and individual tax identification numbers
That, then, is essentially all that's needed to create a parallel identity in the USA.
PayPal did not say whether transaction data and payment card information was also affected but it does say that there were no attempts, successful or otherwise, to make any transactions within the subject accounts. PayPal changed the passwords of the affected accounts to prevent further access. This, of course, means that, if the new passwords are high-security passwords, it's unlikely that a further round of cross-matching between existing publicly available datasets will gain access.
PayPal is to provide each affected user with two years of identity monitoring services from Equifax at no charge.
It appears that none of the affected accounts belonged to users who had implemented two-factor authentication.
PayPal's notice is here: https://www.documentcloud.org/documents/23578067-paypal-notice?responsi…
December was a busy month for this type of hacker: Norton LifeLock also came under attack. See here: https://www.pleasebeinformed.com/publications/ChiefOfficersNetwork_com/…



