Subscribe
Logo
Logo
  • Topics Icon Topics
    • AI Icon AI
    • Banking Icon Banking
    • Blockchain/DeFi Icon Blockchain/DeFi
    • Embedded Finance Icon Embedded Finance
    • Fraud/Identity Icon Fraud/Identity
    • Investing Icon Investing
    • Lending Icon Lending
    • Payments Icon Payments
    • Regulation Icon Regulation
    • Startups Icon Startups
  • Podcasts Icon Podcasts
  • Products Icon Products
    • Webinars Icon Webinars
    • White Papers Icon White Papers
  • TechWire Icon TechWire
  • Search
  • Subscribe
Reading
PayPal’s lack of multi-factor authentication mandate ‘surprising’
ShareTweet
paypal office
Home
Fintech
PayPal’s lack of multi-factor authentication mandate ‘surprising’

PayPal’s lack of multi-factor authentication mandate ‘surprising’

Ricquel Newman·
Payments
·Feb. 8, 2023·3 min read

One security expert was surprised to learn multifactor authentication (MFA) is not mandatory for PayPal users after the company confirmed a data breach occurred in December.

Mike Walters, Co-Founder of Action 1 Corporation, shared his thoughts with Fintech Nexus after the data breach exposed up to 35,000 user accounts.

Mike Walters headshot

Mike Walters

Walters said that the lack of two-layer authentication allowed hackers to get unauthorized access to user accounts through credential stuffing, a simple attack method that relies on stolen credentials.

Walters believes hackers use breached logins and passwords and try all consumers’ accounts until they are successful.

Should MFA be enforced, that attack would not be possible, Walters noted.

Data points possibly compromised in the breach included name, address, Social Security Number, personal tax identification number, and date of birth.

PayPal released a statement shortly after reaffirming its commitment to users’ security:

“Protecting the security of our customers’ information is very important to us. We are writing to inform you about an incident that may have impacted your PayPal account. At the outset, we want to clarify that keeping your data safe and secure will continue to be a priority moving forward.”

What happened?

On Dec. 20, 2022, PayPal confirmed unauthorized parties could access PayPal customer accounts using login credentials. They said that nothing suggested personal information was misused after the breach.

“Upon learning about this unauthorized activity, we promptly began an investigation and took action to address this incident, including by taking steps to prevent unauthorized actors from obtaining further personal information,” the company said in a release.

Related:

BNPL fraud is on the rise: Here’s why

PayPal said they reset the passwords of the affected accounts and implemented enhanced security controls that will require users to establish a new password the next time they log in to their account.

The company also set up Equifax as a partner service to aid in data breach monitoring.

“We have secured the services of Equifax to provide identity monitoring services at no cost to you for two years,” the company said in its statement.

paypal office

What should customers do to protect themselves? 

PayPal users can take a page from the Online Security 101 playbook: Don’t reuse passwords, and don’t err on the side of simple when constructing passwords.

“A lot of people use the same username and password throughout multiple accounts, Gmail, PayPal, and bank accounts just because it’s easier to remember,” Walters said.

He also warned that hackers are getting more sophisticated with direct outreach to potential targets, using spoofing and phishing techniques.

“People should beware of sophisticated social engineering attacks leveraging stolen personally identifiable information (PII),” Walters said. “Attackers might combine various communication channels, such as mail, SMS, messengers, and phone calls, and even personalize their messaging using the information they have stolen in other attacks.”

“If someone reaches out to you and pretends to be PayPal or another organization, never trust; always verify using sources other than those provided by the original sender,” Walters added.

PayPal users who did not receive the notice of the security incident should ensure that the passwords they are using are strong enough (Chrome features a password strength meter when creating new passwords) and haven’t been reused or stolen. Most importantly, enforce MFA for your account if you haven’t done so.

We reached out to PayPal for a statement regarding the breach and did not receive a response.

  • Ricquel Newman
    Ricquel Newman

    Ricquel Newman is a freelance journalist in the San Francisco Bay Area. Prior she was a past journalist for the award-winning consumer news unit, "Seven On Your Side" at ABC7 News in San Francisco. During her 15-year career with ABC News, she produced, managed, and handled all social media for the department. A two-time Emmy Nominee for undercover investigations and light news story features. She is a past radio producer for The Costa Report, a nationally syndicated radio show. Ricquel has a strong passion for news, writing, and creating. She also started her own PR Company at one point. She studied Radio and Television with an emphasis on Broadcast Journalism at San Francisco State University.

    View all posts
Tags
data breachPayPal
Related

Unpacking PayPal’s Missed Moment: 7 Takeaways

BREAKING: Money20/20: The Download

Fiserv’s Sachdev on stablecoins’ evolution

Visa’s Director of Product Management on BNPL’s Future

Popular Posts

Today:

  • FNOura’s CEO Tom Hale on Democratizing Health with AI and Data Mar. 12, 2026
  • Jennifer Lassiter, Standard CharteredScribe CEO Jennifer Smith on what happens when AI joins your team Feb. 26, 2026
  • FNThe Bank Charter Gold Rush: What’s Really Happening and What it Means for Banking Feb. 12, 2026
  • imageAbacum’s CEO: The Future of Finance Looks Like Product Mar. 5, 2026
  • Basis CofoundersFUNDED: Basis Lands $100M as AI Agents Move From Copilots to Full Workflows in Accounting  Feb. 27, 2026
  • Aidan CorbettWayflyer’s $5B Bet on Small Business Lending May. 1, 2025
  • Globe-money-symbolsOPINION: Why Brazil and India are leading the global digital shift through payment innovation Jun. 24, 2025
  • Lin Qiao HDOPINION: Renting Intelligence is a Losing Game; Successful Enterprises Will Own It Jan. 22, 2026
  • 5 Founders Driving Humanoid AIThe Humanoid Era: 5 Leaders Defining Physical AI Sep. 10, 2025
  • Multiply CEO MichaelMultiply Mortgage CEO on AI’s move into housing finance Nov. 6, 2025

This month:

  • FNThe Bank Charter Gold Rush: What’s Really Happening and What it Means for Banking Feb. 12, 2026
  • Santiago SuarezInside Addi’s mission to build a fairer financial system in Colombia Feb. 19, 2026
  • Jennifer Lassiter, Standard CharteredScribe CEO Jennifer Smith on what happens when AI joins your team Feb. 26, 2026
  • Copy of Fintech Nexus – Newsletter Creative (1)Unpacking PayPal’s Missed Moment: 7 Takeaways Feb. 5, 2026
  • FNOura’s CEO Tom Hale on Democratizing Health with AI and Data Mar. 12, 2026
  • The Unintended Consequences of the BaaS CrackdownThe Unintended Consequences of the BaaS Crackdown Apr. 10, 2025
  • imageAbacum’s CEO: The Future of Finance Looks Like Product Mar. 5, 2026
  • Copy of Fintech Nexus – Newsletter CreativeWhy PDF Table Extraction Fails in Production—and What Banks Need to Do About It Feb. 5, 2026
  • Chris Taylor Fractional AIFractional AI’s CEO Chris Taylor on Scaling the Unscalable Jul. 23, 2025
  • TISC Salmon Problem HD“The Salmon Problem” – Building AI For High Stakes Decision Making Jan. 22, 2026

More News
  • About
  • Contact
  • Disclaimer
  • Privacy Policy
  • Terms
Subscribe
Copyright © 2026 Fintech Nexus
  • Topics
    • AI
    • Banking
    • Blockchain/DeFi
    • Embedded Finance
    • Fraud/Identity
    • Investing
    • Lending
    • Payments
    • Regulation
    • Startups
  • Podcasts
  • Products
    • Webinars
    • White Papers
  • TechWire
  • Contact Us
Start typing to see results or hit ESC to close
lis digital banking USA Lending Club UK
See all results