Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Yes—someone can take over an individual PayPal account. That usually involves stolen or reused passwords, phishing, a compromised email account, malware, a hijacked phone number, or a scammer persuading the account holder to share a verification code or approve a payment. It does not, by itself, show that PayPal’s systems were breached.
If you suspect a takeover, open PayPal through its official app or by typing its address yourself. Secure the associated email account, change compromised passwords, review account details and payments, and report any transaction you did not authorize. For U.S. users, the steps below reflect PayPal’s web instructions checked August 18, 2026; labels and available options can vary by account and interface.
What “hacked PayPal” can mean
An unfamiliar PayPal charge is not proof that someone broke into PayPal or even accessed your account. Separate the event into four possibilities, because each can call for a different response:
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →- PayPal platform breach: Unauthorized access to PayPal’s systems. A strange transaction alone does not establish that this occurred.
- Account takeover: Someone signs in using stolen credentials or gains control of a trusted device, email address, phone number, or recovery method.
- Payment fraud without account takeover: A stolen card, fraudulent merchant, fake invoice, or other misuse of a linked payment method creates an unfamiliar charge.
- Authorized-payment scam: A scammer tricks you into approving a payment or sending money yourself. The payment may not be handled the same way as an unauthorized account transaction.
PayPal describes controls such as encrypted connections, fraud monitoring, payment notifications, and passkeys, but these measures cannot make an individual account immune to phishing or social engineering. See PayPal’s overview of its security technology.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How attackers get into PayPal accounts
Reused or exposed passwords
Attackers may try passwords exposed in breaches of other services. Reusing a password lets a compromise elsewhere become a PayPal risk. The FTC recommends unique passwords and explains how stolen credentials can be tested against other accounts in its two-factor authentication guidance.
Phishing and fake support
Messages may claim your account will be closed, a payment failed, a login looks suspicious, or a refund or invoice needs attention. A link can lead to a lookalike login page designed to steal your password. A caller or texter may also pose as PayPal, a bank, or a fraud department to pressure you into disclosing credentials or a code.
Do not use a password-reset link in an unexpected message. Open the PayPal app or type PayPal’s address into a new browser window instead. Sender names, logos, and caller ID are clues, not proof that a message or call is genuine. PayPal says it will not ask for your password or verification code by phone, email, or text. Its account-protection guidance explains how to handle suspicious messages.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteStolen verification codes
A scammer who already has a password may try to obtain the additional login code by impersonating customer support or a fraud team. Never read out or forward a one-time code to someone who contacted you unexpectedly. If you shared one, treat the account as potentially compromised even if you do not yet see a payment.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Compromised email or phone account
Control of the email address attached to PayPal can expose password-reset messages and account notices. The FTC warns that access to an email account may let an attacker reset passwords for other services; see its guidance on passwords and account protection.
A phone-number takeover can expose text-message codes. SMS is better than password-only access, but it depends on your mobile account remaining under your control.
Malware or unsafe devices
Keyloggers, browser-stealing malware, malicious extensions, and remote-access software can reveal passwords or expose an active session. If you suspect a device is infected, do not change account passwords on it. Use a clean device, update the operating system and browser, remove suspicious software or extensions, and run an appropriate security scan.
Signs your account may be compromised
Check for changes or activity you did not make:
- An email address or phone number changed without permission, or you received a password-reset message you did not request.
- A new-device or unusual-login alert appears.
- An unfamiliar payment, withdrawal, transfer, purchase, shipping address, bank account, card, or funding source appears.
- A new automatic payment or subscription was added.
- Security questions or two-step verification settings changed.
- Contacts say they received unexpected messages from your account.
- You are unexpectedly locked out, or PayPal asks for an unusual security check or limits account functions.
PayPal says a security check can be triggered by new or unusual activity, such as a login from a new device or location. Its security-check help page says email or SMS codes may expire after 5–10 minutes; repeated unsuccessful attempts may require waiting 24 hours or contacting PayPal.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What to do if you think your PayPal was hacked
If you can still sign in
- Go to PayPal directly. Use the official app or type the address yourself. Do not click a link in a suspicious message.
- Change your PayPal password. Use a new password that you do not use anywhere else.
- Secure the associated email account. Change its password if it may be exposed or reused; enable multifactor authentication and review recovery details, forwarding rules, devices, and active sessions.
- Change reused passwords elsewhere. Prioritize accounts with access to money, email, mobile service, or password recovery.
- Inspect PayPal account details. Review email addresses, phone numbers, mailing and shipping addresses, linked cards and bank accounts, security questions, and two-step verification settings. Remove changes you did not make.
- Review activity and automatic payments. Check recent transactions and subscriptions for unfamiliar entries.
- Remove unfamiliar payment methods or authorized access. If PayPal offers a control to sign out other sessions or devices, use it.
- Turn on stronger sign-in protection. Set up a passkey or two-step verification if available for your account.
- Secure the device. Update it and scan for malware; change credentials from a clean device if infection is possible.
- Contact your bank or card issuer if a linked financial account or card may also be exposed, or if you see related unauthorized activity.
PayPal’s compromised-account guidance instructs users to change their password and security questions promptly and notes that PayPal may limit account functions until this is done.
If you cannot sign in or account details were changed
- Use PayPal’s official Contact Us page or account-recovery route. Explain that you suspect account takeover and that profile details may have been changed; ask PayPal to secure or temporarily freeze the account.
- Do not call a number from a suspicious email, text, search advertisement, or social-media post.
- Secure your email and mobile-carrier accounts immediately so an attacker cannot use them to regain access.
- Contact linked banks and card issuers about unauthorized activity or exposed payment details.
- Keep evidence: screenshots, transaction IDs, messages and email headers, dates and times, account changes, and device or login alerts.
PayPal says users who believe an unauthorized party accessed their personal data should contact PayPal immediately; PayPal may temporarily freeze the account while investigating. See PayPal’s guidance on suspected unauthorized data access.
Report an unauthorized PayPal transaction
For a U.S. personal account on the web, PayPal’s reported path is:
Recommended Free Tools
- Open the Resolution Center.
- Select Report a problem.
- Choose the suspicious payment.
- Select I want to report unauthorized activity.
- Follow the instructions and keep the case number and correspondence.
PayPal says it will investigate and that you should receive an email within 10 days after filing. That is a notice timeline, not a promise that every claim will be refunded. See PayPal’s unauthorized-transaction instructions.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Before reporting a charge as unauthorized, check whether a family member or other authorized user made it, whether the merchant name differs from the name you recognize, or whether it is a subscription or automatic payment. PayPal’s instructions direct users to review automatic payments under Settings → Payments → Subscriptions and saved businesses or Automatic Payments, depending on the interface. For a completed payment you did authorize but want refunded, contact the merchant where appropriate; a purchase dispute is not the same as an account-takeover report. If a linked bank or card may be involved, contact its issuer as well.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Turn on PayPal two-step verification
PayPal’s current U.S. web instructions list an authenticator app or SMS as setup choices. To configure it:
- Sign in to PayPal in a web browser.
- Click the Settings icon.
- Select Security.
- Select Set Up under 2-step verification.
- Choose an authenticator app or SMS and follow the on-screen steps.
Labels and available options can vary by country, account, device, or interface rollout. If the path differs, look for the equivalent Security or 2-step verification setting in PayPal’s official app or website.
When available, a passkey is a strong first choice. If you use two-step verification instead, an authenticator app is generally safer than SMS because it is not dependent on your phone number or mobile network. SMS remains better than password-only access when other choices are unavailable. The FTC explains these trade-offs in its multifactor-authentication guidance. Plan ahead for a lost or replaced phone, and keep any recovery information PayPal supplies somewhere separate from that device.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Are PayPal passkeys safer?
A passkey lets you sign in using your device’s face or fingerprint recognition, PIN, or passcode instead of typing a PayPal password. It is stored on an eligible device or password manager and is designed to resist common phishing and password-theft attacks. PayPal says biometric data stays on your device and is not shared with PayPal. A passkey reduces specific risks; it does not prevent every kind of fraud, such as a scam that persuades you to approve a payment.
PayPal’s listed eligibility includes iOS 16 or later, macOS Ventura or later, Windows 10 or later, and Android 9 or later, along with specified browser or app versions. Requirements can change; check PayPal’s passkey help for current details and setup instructions.
A lost device does not automatically give someone access to a passkey because the device’s unlock method is still required. If you lose or retire a device, remove its passkey from PayPal and from the device’s password manager or synced passkey service. Removing it from one place may not delete other stored copies. Keep a separate account-recovery route available.
Protect the email account and phone number tied to PayPal
PayPal recovery depends in part on channels outside PayPal. Protect them as carefully as the payment account:
- Use a unique email password and enable multifactor authentication on the email account.
- Review email forwarding rules, recovery addresses, unfamiliar devices, and active sessions; remove anything you do not recognize.
- Add a PIN to your mobile-carrier account and ask the carrier about protections against port-outs or SIM swaps.
- Never share verification codes, even with someone who claims to be investigating fraud.
- Use a clean, updated device for account recovery if malware is suspected.
The FTC generally identifies security keys as the strongest form of two-factor authentication and authenticator apps as safer than SMS. PayPal’s reviewed U.S. setup instructions list authenticator apps and SMS; do not assume a physical security key can be used directly for PayPal sign-in unless that option appears in your own account. A security key can still help protect an email account or password manager that supports it.
Build safer PayPal habits
Use a unique, long password
PayPal recommends a password of at least 12 characters and says not to reuse passwords. A memorable passphrase made from three or more words can be easier to manage than a short, complicated string. Avoid names, birthdays, pet names, phone numbers, and other information people could find publicly. A reputable password manager can generate and store a unique password; protect its vault with a strong master password and multifactor authentication. See PayPal’s account-protection advice.
Review activity and device security
- Pay attention to PayPal payment and security notifications, and check recent activity and automatic payments periodically.
- Keep your operating system, browser, and PayPal app updated. Avoid installing software or browser extensions from untrusted sources.
- Do not treat a login alert, email, or caller ID as proof of identity. Navigate to PayPal independently to check your account.
- Act on linked-bank or card warnings with the bank or issuer directly; changing a PayPal password cannot secure an exposed financial account.
What PayPal protection does not guarantee
Security controls can reduce account-takeover risk, but no login method prevents every scam, malware infection, compromised device session, or unauthorized use of a linked financial account. A payment you approved after being deceived may be treated differently from a payment made by someone who took over your account. Likewise, an unauthorized-transaction investigation and a purchase dispute have different rules. Check PayPal’s applicable terms for the transaction type, and do not assume every loss will automatically be refunded.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

