PayPal says crooks poked around 35,000 accounts in credential stuffing attack
- Reference: 1674171904
- News link: https://www.theregister.co.uk/2023/01/19/paypal_data_breach/
- Source link:
PayPal attributed this privacy breach to "unauthorized parties," who accessed accounts using customer login credentials. That is to say, whoever got into the accounts had found out or guessed their victims' usernames and passwords, possibly by taking the creds from another site where people have reused the same login details.
This is why it's important to use a unique password per site or app you use.
[1]
Information submitted to the Attorney General the US state of Maine revealed this credential-stuffing attack affected [2]34,942 customers on December 6.
[3]
[4]
The exposed information included customers' names, addresses, Social Security numbers, individual tax identification numbers, and dates of birth.
"We have no information suggesting that any of your personal information was misused as a result of this incident, or that there are any unauthorized transactions on your account," the notification letter
[5]PDF
said. "There is also no evidence that your login credentials were obtained from any PayPal systems."[6]
Upon discovering the raid on accounts later in the month, PayPal said it "promptly" launched an investigation and took steps to prevent the crooks from stealing additional customer information — like bank account info, we would assume. Additionally, the payment company reset passwords belonging to affected PayPal accounts, and "implemented enhanced security controls."
PayPal did not inform law enforcement about the security snafu, according to the notification.
The financial goliath did not address The Register 's questions on, among other things, why it didn't involve the cops and what are some of the enhanced security measures it has implemented since discovering the attack. Instead a spinner told us:
Earlier in December, our security team identified and resolved a data incident that affected a small number of PayPal customer accounts.
PayPal’s payment systems were not impacted, and no financial information was accessed. We have contacted affected customers directly to provide guidance on this matter to help them further protect their information. The security and privacy of our customers’ account information remains a top priority for PayPal, and we sincerely apologize for any inconvenience this may have caused.
PayPal is giving affected customers two years of free Equifax services, although the credit monitoring firm doesn't have the best track record when it comes to protecting customer data, either.
In 2017, Equifax was compromised in a cyberattack that the company attributed [7]to the Chinese military in which the attackers stole personal information belonging to about 146.6 million people in the US, Canada, and the UK.
[8]
This latest snafu also happened a couple months after the PayPal implemented added passkeys for [9]passwordless login to accounts across Apple devices in a move to provide customers with a more secure authentication method compared to passwords.
[10]PayPal ditches passwords, at least on Apple devices
[11]Mailchimp 'fesses up to second digital burglary in five months
[12]Ransomware attack severs 1,000 ships from their on-shore servers
[13]For password protection, dump LastPass for open source Bitwarden
According to Microsoft, 579 attacks involving passwords occur every second, or about [14]18 billion a year . Many of them are successful, mainly because people have a tendency to pick poor passwords or reuse them across multiple accounts.
Multi-factor authentication could have prevented this and similar credential-stuffing attacks, according to Timothy Morris, chief security advisor at Tanium.
"This is a prevailing issue where users are using the same id/password combinations for multiple sites and applications," he told The Register , adding that info stolen from PayPal customers could be used for identity theft or sold on hacking forums.
"Credential stuffing is successful because many of those combinations are on the dark web from previous breaches," Morris said. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8of9iXLZkTWqLhZSFmXmQAAAE8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06.shtml
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8of9iXLZkTWqLhZSFmXmQAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8of9iXLZkTWqLhZSFmXmQAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://regmedia.co.uk/2023/01/19/paypal_breach_notification.pdf
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8of9iXLZkTWqLhZSFmXmQAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.equifax.com/newsroom/all-news/-/story/reengineering-a-123-year-old-company-how-equifax-emerged-as-a-high-tech-leader-in-security-and-innovation/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8of9iXLZkTWqLhZSFmXmQAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/10/25/paypal_ditches_passwords/
[10] https://www.theregister.com/2022/10/25/paypal_ditches_passwords/
[11] https://www.theregister.com/2023/01/19/mailchimp_fesses_up_to_2nd/
[12] https://www.theregister.com/2023/01/19/ransomware_attack_cuts_1000_ships/
[13] https://www.theregister.com/2023/01/16/dump_lastpass_bitwarden/
[14] https://www.microsoft.com/security/blog/2021/09/15/the-passwordless-future-is-here-for-your-microsoft-account/
[15] https://whitepapers.theregister.com/
Re: 2FA
You mean send a message to the same compromised cellphone running the app?
My bank now has a number of things that can only be done via the app - and appear totally clueless that they have thus turned 2fa back to 1fa
Re: 2FA
You'd hope, wouldn't you.
I still remember [1]this about PayPal. I try not to use them for commercial payments without a good reason (buyer protection or credit options, basically) but I can say that the flow of the payment process with them is exactly what I expect — I'm always asked to log in with my creds and then asked for my TOTP.
However I only have that flow because I've chosen the appropriate options — 2FA isn't mandatory with PayPal. Furthermore, unless anything's changed since I set it up on my account, they not only offer but actively encourage 2FA via SMS and phone call when you start to set it up. I reckon if PayPal had the balls to require true 2FA, with an authenticator app or hardware key, on all accounts they could change the way the masses think about security overnight.
[1] https://www.theregister.com/2012/01/04/paypal_destroys_violin/
2FA
Surely everyone has 2FA enabled on their account nowadays?