UPDATED 19:52 EDT / JANUARY 19 2023

SECURITY

35,000 PayPal customers affected in credential-stuffing attack

PayPal Holdings Inc. has disclosed a data breach that involved the theft of information from 35,000 customers in a credential-stuffing attack.

In a filing Wednesday with the Office of the Maine Attorney General, PayPal said the breach occurred between Dec. 6 and Dec. 8 and was detected on Dec. 20. Details believed to have been accessed include names, addresses, Social Security numbers, tax identification numbers and dates of birth.

Along with launching an investigation, PayPal reset the passwords of all affected accounts and implemented enhanced security controls. Affected users are also being offered two years of free identity monitoring services from Equifax Inc.

In a credential-stuffing attack, hackers use previously stolen user information from other sites to access other accounts held by those who have had their account details stolen. The attack method relies on people reusing passwords on different sites, a dangerous thing to do in the age of perpetual data breaches but one that is all too common.

“Although many PayPal accounts were affected, the attack was not the result of PayPal’s lack of security,” Paul Bischoff, privacy advocate with tech comparison site Comparitech Ltd., told SiliconANGLE.  “Instead, it’s the result of PayPal users reusing the same password on PayPal and other websites.”

Dr. Ilia Kolochenko, founder of information technology security company ImmuniWeb SA and member of the Europol Data Protection Experts Network, said it’s surprising that multifactor authentication isn’t enforced by default for such a sensitive service as PayPal.

“Modern MFA technologies cost almost nothing to implement and should be enabled by default by financial service providers as a foundational security control,” Kolochenko said. “In the meantime, all users should urgently enable MFA everywhere, especially in view of the recent LastPass data breach.”

The need for improved security was emphasized by Craig Lurey, chief technology officer at password management company Keeper Security Inc. He argues that to prevent credential-stuffing attacks, cloud-based platforms must implement more advanced device verification systems so attackers cannot brute-force test passwords.

“High-profile breaches must serve as a wakeup call for organizations large and small to implement a zero-trust architecture, enable MFA and use strong and unique passwords,” Lurey explained. “It’s equally important to train employees how to identify suspicious phishing emails or text messages that seek to install malware into critical systems, prevent user access and steal sensitive data.”

Image: PayPal

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.