Friday, January 27, 2023
  • Advertise With Us
  • Write For Us
  • Contact Us
  • About Us
  • Editorial Calendar
Download Free Magazine
The Cyber Express
Ransomware 2023 Report
  • Magazine
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacks
    • Ransomware
    • Vulnerabilities
    Verizon

    Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

    GoTo Confirms User Data Stolen With Encryption Key

    GoTo Confirms User Data Stolen With Encryption Key

    HIVE Ransomware

    Hive Ransomware Servers Taken Down in FBI-led Global Law Enforcement Action

    porsche nft

    Porsche NFT Hits Pit Stop, Fake NFT Sale On With Malvertising and Fraud Domains

    Hilton Hotels

    Hilton Hotels Loyalty Program Data Breached, Customer Info for Sale

    League of Legends

    League of Legends Source Code Up For Sale a Day After $10m Ransom Demand, Riot Games Confirm Leak

    Ivory Coast Armed Forces

    About 50GB of Ivory Coast Armed Forces Data on Sale

    KromSec

    Cyber War Against Iran Continues, KromSec Sells Iranian Ministry Database on Hacker Forum

    The Ultimate Guide to Understanding Ransomware Ransomware news

    The Ultimate Guide to Understanding Ransomware: Types, Top Attacks, and How to Protect Yourself

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    Zero Trust Strategy

    US Department of Defense to Embrace Zero Trust Strategy

    browser hijackers

    Researchers Find Browser Hijackers on Google Chrome Web Store

    DORA proposal

    DORA Proposal for Cybersecurity Awaits Full Approval by Council and ESAs

    Privacy penalty bill

    Australia Privacy Penalty Bill 2022: Pay a $50 Million Fine for Data Breaches

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Webinars
    • World CyberCon Middle East 2023
    • Endorsed Events
  • Advertise
No Result
View All Result
The Cyber Express
  • Magazine
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacks
    • Ransomware
    • Vulnerabilities
    Verizon

    Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

    GoTo Confirms User Data Stolen With Encryption Key

    GoTo Confirms User Data Stolen With Encryption Key

    HIVE Ransomware

    Hive Ransomware Servers Taken Down in FBI-led Global Law Enforcement Action

    porsche nft

    Porsche NFT Hits Pit Stop, Fake NFT Sale On With Malvertising and Fraud Domains

    Hilton Hotels

    Hilton Hotels Loyalty Program Data Breached, Customer Info for Sale

    League of Legends

    League of Legends Source Code Up For Sale a Day After $10m Ransom Demand, Riot Games Confirm Leak

    Ivory Coast Armed Forces

    About 50GB of Ivory Coast Armed Forces Data on Sale

    KromSec

    Cyber War Against Iran Continues, KromSec Sells Iranian Ministry Database on Hacker Forum

    The Ultimate Guide to Understanding Ransomware Ransomware news

    The Ultimate Guide to Understanding Ransomware: Types, Top Attacks, and How to Protect Yourself

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    Zero Trust Strategy

    US Department of Defense to Embrace Zero Trust Strategy

    browser hijackers

    Researchers Find Browser Hijackers on Google Chrome Web Store

    DORA proposal

    DORA Proposal for Cybersecurity Awaits Full Approval by Council and ESAs

    Privacy penalty bill

    Australia Privacy Penalty Bill 2022: Pay a $50 Million Fine for Data Breaches

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Webinars
    • World CyberCon Middle East 2023
    • Endorsed Events
  • Advertise
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily Hacks

PayPal Cyberattack: Firm Alerts 35,000 Users, Researcher Says More Than a Million at Risk

Info-stealer infections should be a larger concern to PayPal rather than bruteforce attempts originating from passwords reused from database leaks, says Hudson Rock's Alon Gal

Ashish Khaitan by Ashish Khaitan
January 20, 2023
in Hacks
0
PayPal Cyberattack
606
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

PayPal has notified thousands of its users who have been impacted by a series of credential-stuffing attacks. The company has alerted the 35,000 users it found to be affected. However, more than a million users could be at risk suggested a security researcher.

Alon Gal, Co-Founder and CTO at Hudson Rock, told The Cyber Express that the 35,000 user accounts were likely compromised by bruteforce attempts. Hudson Rock has identified over 1,350,000 PayPal users credentials, which were obtained by hackers as a result of info-stealer infections.

You might also like

Avast Faces DDoS Attack, Days After Security Breach at Parent Firm Gen Digital

United Colors of Benetton’s Italy Nerve Centre Suffers Cyber Attack

Fake Bank Apps Target Loan Applications With Infostealing RAT

“The growing threat of info-stealers infections should be a larger concern to PayPal rather than bruteforce attempts originating from passwords reused from database leaks,” he explained.

Breaking News

Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

Threat actor claims to have access to a database of 7.5 million customers belonging to Verizon, stolen by hackers in January 2023. Read More...

The info-stealers data they collected indicates that over 1,350,000 users credentials are in the hands of hackers, with more getting added every day, according to the Hudson Rock intel. Some compromised credentials of PayPal employees complicate the situation.

PayPal Cyberattack, users at risk

The involved using automated bots to try out the username and password combinations sourced from data leaks on various websites and resulted in unauthorized access to some personal data.

The attacks targeted users who use the same password for multiple online accounts, a common practice known as “password recycling.

PayPal has stated that the attacks were not a result of a breach in their systems, and there is no evidence to suggest that the user credentials were obtained directly from them.

On January 18, 2023, PayPal notified 35,000 users who could have been affected by the data breach. “We want to make clear at the outset that keeping personal data safe and secure is and will continue to be a priority moving forward,” reads the notification email sent by PayPal.

The hackers behind the recent attack were able to gain access to user accounts through credential stuffing. This method uses automated bots to test a list of username and password combinations on websites sourced from past data breaches.

As a result, login portals for multiple services are flooded with these credentials, making it easier for hackers to gain access.

PayPal data leak explained  

According to the notification email sent by PayPal, the online payment giant confirmed a data leak on December 20, 2022. The company stated that “unauthorized parties were able to access” the information of PayPal users using their login credentials. 

Investigation revealed that the attack took place between December 6, 2022, and December 8, 2022. According to PayPal’s notification email, the company was revaluating its third-party partners and the access protocols, which inadvertently glitched and opened the access to third party members.

This allowed hackers, and other potential infiltration parties to view and potentially acquire some personal information, including full name, mailing address, social security number, unique tax identification number, and birthdate for certain PayPal users.

Upon learning about the incident, PayPal started mitigating the attack and resetting the passwords of the affected users, followed by implementing more security controls over the accounts.

PayPal Cyberattack, bigger than imagined

Meanwhile, Gal and his team at Hudson Rock, found that their in-house Hudson Rock info-stealers found data indicating that “over 1,350,000 users’ credentials are in the hands of hackers.

Gal explained that more customer data and login information being added to the leak, including some employee data, indicating a wider risk of user data.

The 35,000 is likely from bruteforce attempts based on information from leaked databases,” Gal told The Cyber Express, explaining the mismatched numbers.

“The 1,350,000 is from computers compromised by info-stealers that also have a login credential to paypal.com.”

Image: Hudson Rock

PayPal is one of the largest online payment platforms in the world. As of 2022, the company had over 429 million active accounts and operated in more than 200 markets, and it’s available in more than 100 currencies.

However, just like any other online account, PayPal can be vulnerable to hacking and cybercrime if not appropriately protected.  

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: PayPal Hacked
Previous Post

Data Breach at T-Mobile, Again!

Next Post

New Malware ‘BoldMove’ Lurking Over FortiOS SSL-VPN Vulnerability Detected

Ashish Khaitan

Ashish Khaitan

Related Posts

DDoS Attack on Avast
Firewall Daily

Avast Faces DDoS Attack, Days After Security Breach at Parent Firm Gen Digital

by Ashish Khaitan
January 27, 2023
United Colors of Benetton
Firewall Daily

United Colors of Benetton’s Italy Nerve Centre Suffers Cyber Attack

by Ashish Khaitan
January 23, 2023
Infostealing RAT
Firewall Daily

Fake Bank Apps Target Loan Applications With Infostealing RAT

by Editorial
January 20, 2023
KelvinSecurity
Firewall Daily

German Institute GIGA Allegedly Attacked by KelvinSecurity

by Ashish Khaitan
January 19, 2023
Genesis Day
Firewall Daily

Genesis Day Claims Responsibility For Samsung Cyber Attack

by Ashish Khaitan
January 19, 2023
Next Post
BoldMove

New Malware 'BoldMove' Lurking Over FortiOS SSL-VPN Vulnerability Detected

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now

Cybersecurity Person of The Year 2023
Download Now

Sign Up For Newsletter

Name*

Recommended

Apple Fixes Vulnerabilities

Apple Fixes Two Major Vulnerabilities in New Update For iOS, iPadOS, and macOS

November 10, 2022
How to Become a Cyber Security Engineer

How to Become a Cyber Security Engineer in 2022

December 1, 2022

Categories

  • Appointments
  • Budgets
  • Business News
  • Compliance
  • Cyber Essentials
  • Cyber Warfare
  • Cybersecurity News
  • Dark Web News
  • Data Breach News
  • DDoS Attacks
  • Espionage
  • Features
  • Firewall Daily
  • Gitex2022
  • Governance
  • Hacks
  • How to
  • Interviews
  • Learning & Development
  • Main Story
  • Malware News
  • Mergers & Aquisitions
  • Partnerships
  • Podcast
  • Policy Updates
  • Press Release
  • Ransomware
  • Regulations
  • Research
  • Resources
  • Startups
  • Vulnerabilities
  • Workforce

Don't miss it

Verizon
Dark Web News

Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

January 27, 2023
GoTo Confirms User Data Stolen With Encryption Key
Data Breach News

GoTo Confirms User Data Stolen With Encryption Key

January 27, 2023
HIVE Ransomware
Cybersecurity News

Hive Ransomware Servers Taken Down in FBI-led Global Law Enforcement Action

January 26, 2023
porsche nft
Firewall Daily

Porsche NFT Hits Pit Stop, Fake NFT Sale On With Malvertising and Fraud Domains

January 26, 2023
DDoS Attacks
DDoS Attacks

Understanding and Preventing Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks: A Comprehensive Guide

January 26, 2023
Hilton Hotels
Data Breach News

Hilton Hotels Loyalty Program Data Breached, Customer Info for Sale

January 27, 2023

About

The Cyber Express

Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

Follow The Cyber Express

Contact

For editorial queries: [email protected]

For marketing, PR & media partnerships: [email protected]

For media kit and digitals sales: [email protected]

For Sponsorship/Event Partnership: [email protected]

For Conferences related information: [email protected]

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

Tel: (678) 578-8838

Subscribe to Our Feed

RSS Feeds

© 2022 The Cyber Express | By Cyble Inc.

No Result
View All Result
  • Firewall Daily
  • Business News
  • Cyber Essentials
  • Features
  • Cybersecurity Magazine
  • Events
    • World CyberCon Middle East 2023
    • Webinars

© 2022 The Cyber Express | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.