Subscribe
Logo
Logo
  • Topics Icon Topics
    • AI Icon AI
    • Banking Icon Banking
    • Blockchain/DeFi Icon Blockchain/DeFi
    • Embedded Finance Icon Embedded Finance
    • Fraud/Identity Icon Fraud/Identity
    • Investing Icon Investing
    • Lending Icon Lending
    • Payments Icon Payments
    • Regulation Icon Regulation
    • Startups Icon Startups
  • Podcasts Icon Podcasts
  • Products Icon Products
    • Webinars Icon Webinars
    • White Papers Icon White Papers
  • TechWire Icon TechWire
  • Search
  • Subscribe
Reading
PayPal’s lack of multi-factor authentication mandate ‘surprising’
ShareTweet
paypal office
Home
Fintech
PayPal’s lack of multi-factor authentication mandate ‘surprising’

PayPal’s lack of multi-factor authentication mandate ‘surprising’

Ricquel Newman·
Payments
·Feb. 8, 2023·3 min read

One security expert was surprised to learn multifactor authentication (MFA) is not mandatory for PayPal users after the company confirmed a data breach occurred in December.

Mike Walters, Co-Founder of Action 1 Corporation, shared his thoughts with Fintech Nexus after the data breach exposed up to 35,000 user accounts.

Mike Walters headshot

Mike Walters

Walters said that the lack of two-layer authentication allowed hackers to get unauthorized access to user accounts through credential stuffing, a simple attack method that relies on stolen credentials.

Walters believes hackers use breached logins and passwords and try all consumers’ accounts until they are successful.

Should MFA be enforced, that attack would not be possible, Walters noted.

Data points possibly compromised in the breach included name, address, Social Security Number, personal tax identification number, and date of birth.

PayPal released a statement shortly after reaffirming its commitment to users’ security:

“Protecting the security of our customers’ information is very important to us. We are writing to inform you about an incident that may have impacted your PayPal account. At the outset, we want to clarify that keeping your data safe and secure will continue to be a priority moving forward.”

What happened?

On Dec. 20, 2022, PayPal confirmed unauthorized parties could access PayPal customer accounts using login credentials. They said that nothing suggested personal information was misused after the breach.

“Upon learning about this unauthorized activity, we promptly began an investigation and took action to address this incident, including by taking steps to prevent unauthorized actors from obtaining further personal information,” the company said in a release.

Related:

BNPL fraud is on the rise: Here’s why

PayPal said they reset the passwords of the affected accounts and implemented enhanced security controls that will require users to establish a new password the next time they log in to their account.

The company also set up Equifax as a partner service to aid in data breach monitoring.

“We have secured the services of Equifax to provide identity monitoring services at no cost to you for two years,” the company said in its statement.

paypal office

What should customers do to protect themselves? 

PayPal users can take a page from the Online Security 101 playbook: Don’t reuse passwords, and don’t err on the side of simple when constructing passwords.

“A lot of people use the same username and password throughout multiple accounts, Gmail, PayPal, and bank accounts just because it’s easier to remember,” Walters said.

He also warned that hackers are getting more sophisticated with direct outreach to potential targets, using spoofing and phishing techniques.

“People should beware of sophisticated social engineering attacks leveraging stolen personally identifiable information (PII),” Walters said. “Attackers might combine various communication channels, such as mail, SMS, messengers, and phone calls, and even personalize their messaging using the information they have stolen in other attacks.”

“If someone reaches out to you and pretends to be PayPal or another organization, never trust; always verify using sources other than those provided by the original sender,” Walters added.

PayPal users who did not receive the notice of the security incident should ensure that the passwords they are using are strong enough (Chrome features a password strength meter when creating new passwords) and haven’t been reused or stolen. Most importantly, enforce MFA for your account if you haven’t done so.

We reached out to PayPal for a statement regarding the breach and did not receive a response.

  • Ricquel Newman
    Ricquel Newman

    Ricquel Newman is a freelance journalist in the San Francisco Bay Area. Prior she was a past journalist for the award-winning consumer news unit, "Seven On Your Side" at ABC7 News in San Francisco. During her 15-year career with ABC News, she produced, managed, and handled all social media for the department. A two-time Emmy Nominee for undercover investigations and light news story features. She is a past radio producer for The Costa Report, a nationally syndicated radio show. Ricquel has a strong passion for news, writing, and creating. She also started her own PR Company at one point. She studied Radio and Television with an emphasis on Broadcast Journalism at San Francisco State University.

    View all posts
Tags
data breachPayPal
Related
paypal

PayPal Q2 Earnings Disappoint – Hope lies in AI

PayPal and Venmo Accepted Here sticker is seen at the entrance to a Panda Express restaurant in Sherwood, Oregon.

Global newsletter: Digital payment apps are not savings accounts

Citing current ‘strong-footing’ for PayPal, CEO plans succession

Fintech Weekly News

Top 10 Fintech News Stories for the Week Ending June 18, 2022

Popular Posts

Today:

  • Ahead of AIOutsmart Pricing Objections Before They Arise with AI Jul. 1, 2025
  • Revised-AI-InvoiceAI Faces Skepticism. Startups Say: OK, Pay When it Works Jun. 25, 2025
  • Stylizedhouse-with-EKGFintech x the One Big Beautiful Bill Jun. 26, 2025
  • Paraform Founders, Jeffrey Li and John KimFunded: Paraform raises $20M to put top recruiters, not AI, in the driver’s seat Jun. 27, 2025
  • Globe-money-symbolsOPINION: Why Brazil and India are leading the global digital shift through payment innovation Jun. 24, 2025
  • GreenliteAI-Alex-WillGreenlite AI is on a mission to revolutionize banking compliance Jun. 10, 2025
  • Current stablecoin adoptionWhy Banks (and Fintechs) Need to Embrace Stablecoins Today Jun. 12, 2025
  • ai-work-nexusWalkMe Vets Declare War on SaaS Bloat with $10M Seed for Autonomous Agents Jun. 10, 2025
  • Email-AI-pieceAvatar CEOs Have Entered the Meeting Jun. 18, 2025
  • DanMurphy-FN-headshotCFPB’s Next Open Banking Battle Begins Jun. 3, 2025

This month:

  • WP UmbrellaTo Bank or Not to Bank: The ILC Question Jun. 5, 2025
  • DanMurphy-FN-headshotCFPB’s Next Open Banking Battle Begins Jun. 3, 2025
  • GreenliteAI-Alex-WillGreenlite AI is on a mission to revolutionize banking compliance Jun. 10, 2025
  • Current stablecoin adoptionWhy Banks (and Fintechs) Need to Embrace Stablecoins Today Jun. 12, 2025
  • ai-work-nexusWalkMe Vets Declare War on SaaS Bloat with $10M Seed for Autonomous Agents Jun. 10, 2025
  • Ben Hemani, Founding Partner at Bison VenturesThe Risk and Reward of Betting Big on AI’s Next Frontier Jun. 4, 2025
  • Jon StonaTips from Airwallex x McLaren on Making the Best of a Fintech Sponsorship  Jun. 18, 2025
  • Ironclad State of AI ReportThe Economics of AI Trust Jun. 11, 2025
  • Email-AI-pieceAvatar CEOs Have Entered the Meeting Jun. 18, 2025
  • TechNexus The AI IssueMeeker’s AI Bombshell + The VC Betting on AI Reshaping The Physical World  Jun. 4, 2025

  • About
  • Contact
  • Disclaimer
  • Privacy Policy
  • Terms
Subscribe
Copyright © 2025 Fintech Nexus
  • Topics
    • AI
    • Banking
    • Blockchain/DeFi
    • Embedded Finance
    • Fraud/Identity
    • Investing
    • Lending
    • Payments
    • Regulation
    • Startups
  • Podcasts
  • Products
    • Webinars
    • White Papers
  • TechWire
  • Contact Us
Start typing to see results or hit ESC to close
lis digital banking USA Lending Club UK
See all results