PayPal has informed over 34,000 users that their personal data has been breached by a credential stuffing attack.
The attack took place between December 6 and December 8 2022. While the company had realised the attack and worked to mitigate and investigate what occurred, users were only just notified that their personal data had been accessed by an unauthorised third party.
In the statement released to affected parties, PayPal says that there is no evidence any information was misused, and also no evidence of unapproved transactions on people’s accounts.
Personal information was accessed – including names, addresses, Social Security numbers, individual tax identification numbers, and date of birth – from 34,942 users.
To prevent further information getting exposed, PayPal claims they promptly reset passwords of affected PayPal accounts and put in place more stringent security measures, requiring users to establish a new password the next time they logged into their account.
In their notification to affected users, PayPal made no mention if the hackers could have accessed credit or debit card information, as well as banking details, that are often stored on PayPal accounts.
The method of hacking would likely give the attackers access to full accounts: credential stuffing often uses bots to ‘stuff’ an account with username and password combinations sourced from various other data leaked websites.
With a successful combination, a third party would have full access to an account, though PayPal claims to have found no evidence of misuse of information or incorrect transactions in their investigation.
PayPal has given users access to Equifax to provide identity monitoring services for two years to help them monitor the after effects of the data breach.
In their notification, PayPal also encourages users to change their passwords across all their accounts to new, unique combinations, as well as considering enabling two-step verification.
Credential stuffing is most effective against users who use the same password for multiple accounts.
The notification also warned users against potential phishing scams, encouraging them to check URLs and not to ever disclose their username and password or other authentication factors.
After yet another cyber-attack, specialists felt the need to respond.
“This incident highlights there is no data on the dark web that goes unnoticed, or unused,” Mark Lamb CEO of HighGround.io, said.
“PayPal customers that have had their accounts accessed must have featured in a previous data breach and when an attacker got hold of their passwords and emails, they used an automated credential stuffing attack to test them out against other sites, which then granted them with access to PayPal.
“Anyone impacted by this incident must change their passwords now, not only for their PayPal account, but also for any other sites using the same access credentials.
“When it comes to protecting against these threats, it is critical that internet users are taught about the importance of utilising strong and unique passwords. Organisations can also add additional security layers by implementing multi-factor authentication and implementing technology which has the ability to detect mass logins over a short period of time, which is often the number red flag warning of a credential stuffing attack.”
Recommended
- Linux Malware Hit Record Highs in 2022
- UK IT Firms Subject to More Than One Cyber-attack Every Week
- Is Bitcoin Back on the Charge After a Rough 12 Months?
Julia O’Tool, CEO of MyCena Security Solutions, said: “This is yet another credential stuffing attack that has been announced in the last few days, and it once again shows how attackers constantly scrape data from the dark web to exploit compromised information further.
“PayPal has stated that it has no evidence of user accounts being used maliciously, but this should provide little comfort for victims. The attackers can now target these victims with phishing emails and identity theft scams and use those passwords again on other sites.
“This incident highlights the unrealistic expectation of individuals having to create and remember unique passwords for all their online accounts. It’s the reason why many people use variations of the same password for all their accounts, including for their password manager account.”
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





