Skip to content
General

Nearly 35,000 PayPal user accounts were hacked due to reused passwords

By Wei Zhang
2 min read
Paypall option
Paypall option
In this article (4)

Nearly 35,000 PayPal user accounts have been breached by so-called “credential stuffing”. PayPal managed to stop the two-day intrusion and reset the affected users’ passwords.

In fact, PayPal’s own servers weren’t hacked. The reason for the hack was the so-called “credential stuffing”, a technique the hackers used to gain access to the user accounts. This type of attack is when a hacker uses previously leaked login info – and if the user has reused it for their PayPal account, the hacker can get access.

The intrusion reportedly lasted two days, between December 6 and December 8, 2022, and it affected 34,942 user accounts. It is possible that the hackers were able to access a significant amount of personal information for the affected users, including full names, birth dates, postal addresses, social security numbers, and individual tax identification numbers. On top of that, hackers had access to transaction histories, connected credit and debit card details, and PayPal invoicing data.

However, PayPal was able to stop the attack and reset the passwords for the users so the hackers would lose access. The popular online payments platform reassures that no unauthorized transactions were attempted. The affected users also get two free years of credit monitoring from Equifax.

All in all, this could have become a very bad situation if the hackers were trying to make transactions from the affected users’ accounts. Fortunately, this didn’t happen. The entire situation shows that not reusing the same password across platforms (especially PayPal or other payment platforms) is of primary importance.

Basically, PayPal wasn’t hacked; so if the users had not reused passwords, they wouldn’t have been hacked either. So, better not to reuse passwords. If you’re having trouble remembering all your passwords, you can use a service like 1Password or other password managers. Also, you can benefit from PayPal’s two-factor authentication for an even tighter security of your account.

Questions & Answers

Q.

What information might the hackers have accessed from the affected PayPal accounts?

A.

Hackers may have accessed full names, birth dates, postal addresses, social security numbers, and individual tax identification numbers. They also had access to transaction histories, connected card details, and PayPal invoicing data.

Q.

Were any unauthorised transactions made from the breached accounts?

A.

No, the online payments platform has stated that no unauthorised transactions were attempted. PayPal managed to stop the intrusion and reset passwords before any transactions could occur.

Q.

How long did the credential stuffing attack last?

A.

The intrusion reportedly lasted for two days. It occurred between 6th December and 8th December 2022, before PayPal stopped the attack and reset the affected users' passwords.

Reader pulse

How concerned are you about credential stuffing attacks?

24,079 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready