Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 9 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

35,000 PayPal Accounts Hacked

Credential stuffing attacks have allowed cybercriminals unauthorised access to thousands of PayPal accounts

by Guru Writer
January 20, 2023
in Featured
35,000 PayPal Accounts Hacked
Share on FacebookShare on Twitter

A security notification released to PayPal customers this morning has revealed that up to 35,000 customers have fallen victim to a credential stuffing attack. Credential stuffing attacks involve bad actors systematically trying username and password combinations in order to break into an account. This means that PayPal itself was not hacked – only the accounts of affected customers. 

Credential stuffing attacks such as this are a key driver of the security industry’s insistence on good password hygiene, using unique, complex pass-phrases that are unlikely to be guessed. 

“In the online age, where every website wants a user to have an account, it is easy to understand why people will re-use the same username & password combination. Research suggests that 0.1% of leaked credentials will be valid on another platform – Whilst this sounds like a small amount, leaked credentials number into the billions (services like haveibeenpwned list counts by breach),” said Mike Varley, threat consultant at Adarma. 

“Credential stuffing differs from brute force attacks in that they use valid credentials from other platforms. Combine this with a botnet originating from multiple different sources and you have an attack that can defeat most login protections, such as geoblocking and/or rate limiting,” he continued. 

Despite PayPal itself not being hacked, some experts have expressed the need for platforms to implement better password practices on their user’s behalf. 

“To prevent credential stuffing attacks, cloud-based platforms must implement more advanced device verification systems, so that attackers cannot brute force test passwords. A secure password manager such as Keeper will prevent password attempts on an account if the device being used is not verified and approved by the user. This device verification system inherently creates a second factor without requiring the end-user to go through manual steps to protect their account,” said Craig Lurey, CTO and co-founder of Keeper Security. 

ShareTweet
Previous Post

KnowBe4 2022 Phishing Test Report Confirms Business-Related Emails Trend 

Next Post

T-Mobile Data Breach: 37 million customers affected

Recent News

Zimperium Expands UK Presence with ABC Distribution Partnership

Zimperium Expands UK Presence with ABC Distribution Partnership

June 9, 2026
Forescout Wins SC Awards Europe 2026 for Best IoT/IIoT Security Solution

Forescout Wins SC Awards Europe 2026 for Best IoT/IIoT Security Solution

June 9, 2026
Is Offensive Security Keeping Up with the Latest Cyber Attacks?

Is Offensive Security Keeping Up with the Latest Cyber Attacks?

June 9, 2026
Filigran uses AI agents to make CTEM practical for overstretched security teams

Filigran uses AI agents to make CTEM practical for overstretched security teams

June 9, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol