The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Between December 6 and 8, 2022, an attacker used credentials apparently obtained outside PayPal to log in to 34,942 PayPal accounts. PayPal said it found no evidence that the login credentials came from its own systems. The incident was unauthorized access to customer accounts—not a confirmed theft of PayPal’s password database.
What happened in the PayPal incident?
PayPal detected automated login attempts that succeeded against 34,942 accounts. The company said it eliminated the unauthorized access on December 8, 2022. It later told affected users that the credentials were likely obtained through phishing or related activity unrelated to PayPal, but did not identify a specific source. The incident was publicly reported in January 2023.
| Date | What happened |
|---|---|
| December 6–8, 2022 | Unauthorized access to PayPal accounts occurred using valid credentials. |
| December 8, 2022 | PayPal said it eliminated the access and began containment. |
| January 18, 2023 | PayPal submitted a breach notice to the Maine Attorney General. |
| January 19, 2023 | The incident was publicly reported. |
The dates and response details are in PayPal’s notice filed with Maine. The 34,942-account figure is also reported by the Massachusetts cybercrime bulletin.
Was PayPal itself hacked?
PayPal accounts were accessed without authorization, but the available evidence does not establish that attackers breached PayPal’s internal credential database. PayPal’s notice said there was no evidence that the login credentials were obtained from PayPal systems. The more precise description is account takeover through credential stuffing, not a confirmed theft of PayPal’s password store.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What is credential stuffing?
Credential stuffing is an automated attempt to log in to a service using username-and-password pairs exposed elsewhere. Unlike a brute-force attack, it does not depend primarily on guessing passwords: attackers try combinations that may already have worked on another site. Reusing a password lets a compromise at one service become a route into another. The Massachusetts bulletin describes the method as automated use of credentials sourced from data leaks.
Phishing can be one way credentials are stolen, but it is not the same thing as credential stuffing. In this case, PayPal said phishing or related activity was a likely source, without establishing the exact origin.
What information may have been exposed?
The exposed information was not necessarily identical for every account. In its filing, PayPal listed the following categories for affected Maine residents, saying one or more may have been involved:
Rank #2
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
- Name and address
- Social Security number or individual tax identification number
- Phone number
- Date of birth
The filing’s data categories apply to the affected Maine residents it describes; they do not establish that all 34,942 accounts had Social Security numbers or tax IDs exposed. Reporting also said an intruder could view account information such as transaction history, connected card details, and invoicing information, but that should not be read as proof that every account contained or exposed the same details.
A successful account login can reveal information held in that account. That is different from evidence that every visible item was copied, misused, or exposed in the same way.
Did PayPal report unauthorized transactions?
At the time of its breach notice, PayPal said it had no information indicating that exposed information had been misused or that unauthorized transactions had occurred on affected accounts. That is a statement about what PayPal knew then, not a guarantee against later fraud or identity misuse. Check activity and report anything unfamiliar through PayPal’s official Security Center.
Rank #3
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
What did PayPal do?
According to the Maine filing, PayPal eliminated the unauthorized access, reset passwords for affected accounts, masked exposed personal information, investigated with outside counsel, implemented additional security controls, and sent notifications.
What should affected PayPal users do?
- Go to PayPal directly. Type PayPal.com into your browser or open the official app. Do not use a link in an unexpected breach email or text.
- Change your PayPal password. Choose a new, unique password that you do not use for another account.
- Change reused passwords elsewhere. Prioritize your email, banking, shopping, cloud-storage, and social-media accounts. A reused password can put those accounts at risk even if PayPal has reset yours.
- Turn on two-step verification. In a web browser, open Settings → Security → Set Up under 2-step verification. PayPal’s account-security guidance documents this path and describes available verification choices.
- Secure the email account connected to PayPal. Set a unique password, enable multifactor authentication if available, and review recovery details. Someone who controls your inbox may be able to reset passwords or intercept account notices.
- Review your PayPal account. Check recent transactions, automatic payments, linked bank accounts and cards, addresses, and contact details. Also check your bank and card statements directly.
- Report unfamiliar activity through PayPal. Use the official site or app rather than a phone number or link supplied in an unsolicited message.
- If your notice says a Social Security number or tax ID was exposed, watch for identity-theft indicators and consider a credit freeze or fraud alert. Follow official identity-theft guidance, not services promoted in unsolicited calls or messages.
The FTC’s data-breach guidance likewise recommends changing the exposed password and any reused passwords, enabling multifactor authentication, and checking which information was affected.
How to avoid follow-up scams
A message that mentions a real incident is not necessarily a genuine PayPal notice. Go to PayPal by typing its address yourself and check account notifications after signing in. Do not give an unsolicited caller your password, one-time verification code, Social Security number, or full card details. PayPal’s security guidance says it will not ask you to provide a verification code by phone, email, or text.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
If you cannot sign in, use PayPal’s password-recovery flow by navigating to PayPal directly. Check whether your account email or phone number has changed, secure your email account, and then contact PayPal through its official Security Center or Help Center. Avoid repeated recovery attempts through links sent by strangers.
What remains unclear
PayPal did not identify the precise source of the credentials, and the information available does not show that every affected account exposed the same data. PayPal’s no-known-misuse statement reflects its position at the time of notification; it does not establish that later misuse was impossible.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




