Security News

PayPal files patent for new method to detect stolen cookies
2024-02-25 16:02

"The theft of cookies is a sophisticated form of cyberattack, where an attacker steals or copies cookies from a victim's computer onto the attacker's web browser," PayPal says in the patent application. "With stolen cookies often containing hashed passwords, the attacker can use a web browser on the attacker's computer to impersonate the user and gain access to secure information associated with the user's account without having to manually login or provide authentication credentials," it is further explained.

Police use of PayPal records under fire after raid on 'Cop City' protest fund trio
2023-06-06 23:03

Three supporters of activists against a $90 million police training facility dubbed Cop City were arrested after the cops used PayPal data to bring money-laundering charges against the trio. Police cuffed 39-year-old Marlon Scott Kautz and 42-year-old Adele Maclean, both of Atlanta, Georgia, and 30-year-old Savannah Patterson, of Savannah, and charged them with money laundering and charity fraud at the end of May. The three, as board members of the Atlanta Solidarity Fund, help arrange legal advice, bail funds, and other support for those who oppose the southern US state's Cop City and run into trouble with the authorities.

PayPal and Twitter abused in Turkey relief donation scams
2023-02-09 11:00

Scammers are now exploiting the ongoing humanitarian crisis in Turkey and Syria: this time stealing donations by abusing legitimate platforms like PayPal and Twitter. BleepingComputer has identified multiple scams running on Twitter and abusing legitimate platforms like PayPal's fundraising pages to create convincing scam websites and collect proceeds from donors hoping to aid earthquake victims.

PayPal says crooks poked around 35,000 accounts in credential stuffing attack
2023-01-19 23:45

The personal information of 35,000 PayPal users was exposed in December, according to a notification letter sent to the online payment company's customers this week. PayPal attributed this privacy breach to "Unauthorized parties," who accessed accounts using customer login credentials.

PayPal accounts breached in large-scale credential stuffing attack
2023-01-19 14:47

PayPal is sending out data breach notifications to thousands of users who had their accounts accessed through credential stuffing attacks that exposed some personal data. Credential stuffing are attacks where hackers attempt to access an account by trying out username and password pairs sourced from data leaks on various websites.

Black Friday and retail season – watch out for PayPal “money request” scams
2022-11-17 20:45

The bad thing about this scam is that it's astonishingly easy for criminals to set up, and it carefully avoids sending spoofed emails or tricking you to visit bogus websites, because the crooks use a PayPal service to generate their initial contact via official PayPal servers. Email scammers therefore often go out of their way to ensure that their first contact with potential victims involves messages that really do come from genuine sites or online services, and that link to servers that really are run by those same legitimate sites.

PayPal ditches passwords, at least on Apple devices
2022-10-25 19:30

PayPal has added passkeys for passwordless login to accounts across Apple devices. Passkeys allows users to login to accounts with cryptographic key pairs instead of passwords.

Clever Phishing Scam Uses Legitimate PayPal Messages
2022-09-01 12:18

Brian Krebs is reporting on a clever PayPal phishing scam that uses legitimate PayPal messaging. Basically, the scammers use the PayPal invoicing system to send the email.

Steam, PayPal blocked as Indonesia enforces new Internet regulation
2022-08-01 17:09

The Indonesian Ministry of Communication and Information Technology, Kominfo, is now blocking access to internet service and content providers who had not registered on the country's new licensing platform by July 27th, 2022, as the country begins to restrict access to online content providers and services. The first blocks began Friday, a day before the June 26th deadline, and according to internet access monitoring org NetBlocks, some of the service providers include Yahoo, Steam, and PayPal.

PayPal phishing kit added to hacked WordPress sites for full ID theft
2022-07-14 18:09

A newly discovered phishing kit targeting PayPal users is trying to steal a large set of personal information from victims that includes government identification documents and photos. The kit is hosted on legitimate WordPress websites that have been hacked, which allows it to evade detection to a certain degree.