Log in links for this page

Cybercrimes and Scams - 2023

Stories and headlines related to cybercrimes and scams, digital hygiene and privacy, and other consumer-related bulletins.

Table of Contents

January

PayPal accounts breached in large-scale credential stuffing attack

PUBLISHED: January 19th, 2023

PayPal is sending out data breach notifications to thousands of users who had their accounts accessed through credential stuffing attacks that exposed some personal data.

Credential stuffing are attacks where hackers attempt to access an account by trying out username and password pairs sourced from data leaks on various websites. This type of attack relies on an automated approach with bots running lists of credentials to "stuff" into login portals for various services. Credential stuffing targets users that employ the same password for multiple online accounts, which is known as "password recycling."

According to the data breach reporting from PayPal, 34,942 of its users have been impacted by the incident. During the two days, hackers had access to account holders' full names, dates of birth, postal addresses, social security numbers, and individual tax identification numbers. Transaction histories, connected credit or debit card details, and PayPal invoicing data are also accessible on PayPal accounts.

PayPal says it took timely action to limit the intruders' access to the platform and reset the passwords of accounts confirmed to have been breached.

"We have no information suggesting that any of your personal information was misused as a result of this incident, or that there are any unauthorized transactions on your account," reads PayPal's notification to impacted users.

Sources:

PayPal accounts breached in large-scale credential stuffing attack | Bleeping Computer

 

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback