Subscribe
Logo
Logo
  • Topics Icon Topics
    • AI Icon AI
    • Banking Icon Banking
    • Blockchain/DeFi Icon Blockchain/DeFi
    • Embedded Finance Icon Embedded Finance
    • Fraud/Identity Icon Fraud/Identity
    • Investing Icon Investing
    • Lending Icon Lending
    • Payments Icon Payments
    • Regulation Icon Regulation
    • Startups Icon Startups
  • Podcasts Icon Podcasts
  • Products Icon Products
    • Webinars Icon Webinars
    • White Papers Icon White Papers
  • TechWire Icon TechWire
  • Search
  • Subscribe
Reading
PayPal’s lack of multi-factor authentication mandate ‘surprising’
ShareTweet
paypal office
Home
Fintech
PayPal’s lack of multi-factor authentication mandate ‘surprising’

PayPal’s lack of multi-factor authentication mandate ‘surprising’

Ricquel Newman·
Payments
·Feb. 8, 2023·3 min read

One security expert was surprised to learn multifactor authentication (MFA) is not mandatory for PayPal users after the company confirmed a data breach occurred in December.

Mike Walters, Co-Founder of Action 1 Corporation, shared his thoughts with Fintech Nexus after the data breach exposed up to 35,000 user accounts.

Mike Walters headshot

Mike Walters

Walters said that the lack of two-layer authentication allowed hackers to get unauthorized access to user accounts through credential stuffing, a simple attack method that relies on stolen credentials.

Walters believes hackers use breached logins and passwords and try all consumers’ accounts until they are successful.

Should MFA be enforced, that attack would not be possible, Walters noted.

Data points possibly compromised in the breach included name, address, Social Security Number, personal tax identification number, and date of birth.

PayPal released a statement shortly after reaffirming its commitment to users’ security:

“Protecting the security of our customers’ information is very important to us. We are writing to inform you about an incident that may have impacted your PayPal account. At the outset, we want to clarify that keeping your data safe and secure will continue to be a priority moving forward.”

What happened?

On Dec. 20, 2022, PayPal confirmed unauthorized parties could access PayPal customer accounts using login credentials. They said that nothing suggested personal information was misused after the breach.

“Upon learning about this unauthorized activity, we promptly began an investigation and took action to address this incident, including by taking steps to prevent unauthorized actors from obtaining further personal information,” the company said in a release.

Related:

BNPL fraud is on the rise: Here’s why

PayPal said they reset the passwords of the affected accounts and implemented enhanced security controls that will require users to establish a new password the next time they log in to their account.

The company also set up Equifax as a partner service to aid in data breach monitoring.

“We have secured the services of Equifax to provide identity monitoring services at no cost to you for two years,” the company said in its statement.

paypal office

What should customers do to protect themselves? 

PayPal users can take a page from the Online Security 101 playbook: Don’t reuse passwords, and don’t err on the side of simple when constructing passwords.

“A lot of people use the same username and password throughout multiple accounts, Gmail, PayPal, and bank accounts just because it’s easier to remember,” Walters said.

He also warned that hackers are getting more sophisticated with direct outreach to potential targets, using spoofing and phishing techniques.

“People should beware of sophisticated social engineering attacks leveraging stolen personally identifiable information (PII),” Walters said. “Attackers might combine various communication channels, such as mail, SMS, messengers, and phone calls, and even personalize their messaging using the information they have stolen in other attacks.”

“If someone reaches out to you and pretends to be PayPal or another organization, never trust; always verify using sources other than those provided by the original sender,” Walters added.

PayPal users who did not receive the notice of the security incident should ensure that the passwords they are using are strong enough (Chrome features a password strength meter when creating new passwords) and haven’t been reused or stolen. Most importantly, enforce MFA for your account if you haven’t done so.

We reached out to PayPal for a statement regarding the breach and did not receive a response.

  • Ricquel Newman
    Ricquel Newman

    Ricquel Newman is a freelance journalist in the San Francisco Bay Area. Prior she was a past journalist for the award-winning consumer news unit, "Seven On Your Side" at ABC7 News in San Francisco. During her 15-year career with ABC News, she produced, managed, and handled all social media for the department. A two-time Emmy Nominee for undercover investigations and light news story features. She is a past radio producer for The Costa Report, a nationally syndicated radio show. Ricquel has a strong passion for news, writing, and creating. She also started her own PR Company at one point. She studied Radio and Television with an emphasis on Broadcast Journalism at San Francisco State University.

    View all posts
Tags
data breachPayPal
Related

Unpacking PayPal’s Missed Moment: 7 Takeaways

BREAKING: Money20/20: The Download

Fiserv’s Sachdev on stablecoins’ evolution

Visa’s Director of Product Management on BNPL’s Future

Popular Posts

Today:

  • FNInside Parafin’s Push to Close Small Business Finance’s $2 Trillion Gap Jun. 4, 2026
  • Private Fintech Has Quietly Become Bigger Than Public Fintech. Now What?Private Fintech Has Quietly Become Bigger Than Public Fintech. Now What? May. 28, 2026
  • Stephanie Sher, Founder, Integral VenturesIntegral Ventures’ Stephanie Sher is all about seeing diamonds in the rough May. 14, 2026
  • SOLO CeoSOLO’s CEO on the data and banking dilemma Sep. 11, 2025
  • FundedFunded: Zenskar lands $15M to rebuild billing for AI-era finance teams Apr. 17, 2026
  • HumanX_recapHumanX: Between Prophecy and Procurement Apr. 9, 2026
  • Fonoa (2)Funded: Fonoa raises $110M to build the operating system for autonomous tax May. 29, 2026
  • Chris Taylor Fractional AIFractional AI’s CEO Chris Taylor on Scaling the Unscalable Jul. 23, 2025
  • FundedFUNDED: Highlight AI raises $40M to fix the coordination mess AI created Mar. 27, 2026
  • 2026 FintechWhat does 2026 hold for Fintech?  Jan. 29, 2026

This month:

  • FNInside Parafin’s Push to Close Small Business Finance’s $2 Trillion Gap Jun. 4, 2026
  • FNMerge CEO on building the pipes behind AI, and starting with zero code May. 21, 2026
  • FN“A race against time” – Fenrock AI’s CEO on fighting the impending wave of AI fraud May. 7, 2026
  • Private Fintech Has Quietly Become Bigger Than Public Fintech. Now What?Private Fintech Has Quietly Become Bigger Than Public Fintech. Now What? May. 28, 2026
  • Stephanie Sher, Founder, Integral VenturesIntegral Ventures’ Stephanie Sher is all about seeing diamonds in the rough May. 14, 2026
  • Chris Taylor Fractional AIFractional AI’s CEO Chris Taylor on Scaling the Unscalable Jul. 23, 2025
  • What is Really Going on With Private CreditWhat is Really Going on With Private Credit Apr. 30, 2026
  • FNThe Bank Charter Gold Rush: What’s Really Happening and What it Means for Banking Feb. 12, 2026
  • MomentFunded: Moment raises $36M Series B to automate fixed income for financial institutions Jul. 18, 2025
  • How Traversal Prevents Million-Dollar OutagesHow Traversal Prevents Million-Dollar Outages Apr. 30, 2026

More News
  • About
  • Contact
  • Disclaimer
  • Privacy Policy
  • Terms
Subscribe
Copyright © 2026 Fintech Nexus
  • Topics
    • AI
    • Banking
    • Blockchain/DeFi
    • Embedded Finance
    • Fraud/Identity
    • Investing
    • Lending
    • Payments
    • Regulation
    • Startups
  • Podcasts
  • Products
    • Webinars
    • White Papers
  • TechWire
  • Contact Us
Start typing to see results or hit ESC to close
lis digital banking USA Lending Club UK
See all results