Categories: Tech

Social Security Numbers Stolen In PayPal Cyber Attack

Another reason why you should set good passwords and use two-factor authentication.
Sarah Tew/CNET

The Social Security numbers and other personal information of about 35,000 PayPal users was stolen in a December credential-stuffing attack, the company said in a Wednesday regulatory filing.

According to a documents filed with the state of Maine, the attack occurred between Dec. 6 and Dec. 8 of last year and was discovered on Dec. 20. In addition to Social Security numbers, user names, addresses, dates of birth and individual tax identification numbers also may have been compromised.

There’s no indication that any financial information was stolen, or that customer accounts were misused, PayPal said. The company’s payment systems were also not affected.

In a statement released to CNET on Thursday, PayPal said it has contacted affected customers and offered guidance on how to further protect their personal information. The company also reset the passwords of all of the affected accounts and is requiring their users to set new ones the next time they log in.

PayPal is also providing those affected with identity theft monitoring services through Equifax for the next two years,

In a credential-stuffing attack, cybercriminals bombard online accounts with combinations of user names and passwords, often stolen in previous data breaches, in an attempt to access as many accounts as possible.

That’s a big reason why cybersecurity experts say consumers should always enable two-factor authentication whenever possible. The security measure requires a second form of authentication, like a fingerprint or a code sent to a user’s phone, in addition to a password, protecting a user in the event their password is compromised.

In addition, people should always use long, unique and random passwords for each of their online accounts. Those will be less likely to show up on the lists of passwords used to crack accounts in credential-stuffing attacks.

Read More:

  • Best Payment Apps for 2023: Apple Cash, Cash App, PayPal and More
  • How to Delete Your PayPal Account Permanently
  • LastPass says no passwords compromised in latest security scare
Share

Recent Posts

Iran acknowledges death toll from Israel’s strike on notorious Evin prison

close Video Trump dismisses notion that Iran hid uranium Maria Bartiromo speaks to President Donald…

1 hour ago

Exiled Iranian prince tells Trump he can be ‘one of history’s great peacemakers’ amid talk of regime change

close Video The Achilles heel of Iran's regime is the people, says Lisa Daftari 'Fox…

12 hours ago

Trump pressures Israel to end Gaza conflict as he eyes Abraham Accords expansion

close Video Trump says more nations want to expand ties with Israel under Abraham Accords…

12 hours ago

Iran’s nuclear capabilities crushed, but regime’s desire for the bomb may persist

close Video Sec. Hegseth, Gen. Caine reveal 'Midnight Hammer' operation details U.S. Secretary of Defense…

16 hours ago

Ukraine moves toward withdrawing from treaty banning anti-personnel mines

close Video Putin says Russia is ‘ready’ for third round of peace talks with Ukraine…

16 hours ago

UK punk-rap duo sparks outrage with anti-Israel chants at major music festival

close Video Punk-Rap duo Bob Vylan shouts anti-Israel rhetoric during Glastonbury Festival The Punk-Rap duo…

1 day ago