Menu
Browse

Cyber Incident Victim: PayPal

Date:

Dec 2022

Location:

United States of America

Summary

PayPal experienced a data breach resulting from a credential-stuffing attack, where unauthorized parties accessed customer accounts using compromised login credentials. The intrusion exposed sensitive personal information including names, addresses, Social Security numbers, tax identification numbers, and dates of birth. The company identified unauthorized account access over a two-day period, initiated an investigation, and confirmed data exfiltration before notifying affected individuals. Impacted users received breach notification letters detailing the compromised information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

PayPal detected unauthorized access to customer accounts between December 6 and December 8, 2022, later confirmed to be the result of a credential-stuffing attack. The company discovered the breach on December 20, 2022, when it identified that attackers had successfully logged into accounts using compromised credentials. An immediate investigation revealed the attackers maintained access for a three-day window, during which they viewed and potentially exfiltrated sensitive personal information. PayPal determined the attackers targeted an undisclosed number of customer accounts through automated login attempts using credentials presumably obtained from unrelated third-party breaches. The company's security team contained the incident by December 8, though full discovery of the breach's scope required extended forensic analysis lasting approximately one month.

Cyber Incident Image

The compromised data included full names, physical addresses, Social Security numbers, individual tax identification numbers, and dates of birth – sufficient information to enable identity theft and financial fraud. PayPal completed its review of affected records by January 18, 2023, when it simultaneously filed a breach notification with the Maine Attorney General's Office and initiated consumer notification letters. The breach impacted an undisclosed number of PayPal's 426 million active users, though the company confirmed the attackers only accessed accounts where credentials were successfully matched. No evidence suggested compromise of PayPal's internal systems or infrastructure, as the attack exploited reused customer credentials rather than system vulnerabilities. Financial transaction data and passwords reportedly remained secure, with the breach limited to personal identification information stored in user profiles.

Sources
Sources available to members
1 source