Article Details
Paypal data stolen?Why Darknet scanner now only helps a limited extent
Published on August 22, 2025
Popular browser expansion makes screenshots on every page that you visit
Popular browser expansion makes screenshots on every page that you visit
2.5 billion Gmail accounts threatened: How to protect yourself now
2.5 billion Gmail accounts threatened: How to protect yourself now
Warning of call fraud: Your money is in danger - this is how you react correctly
Warning of call fraud: Your money is in danger - this is how you react correctly
Those of seconds: AI cracks passwords at lightning speed - how you protect yourself
Those of seconds: AI cracks passwords at lightning speed - how you protect yourself
Fraud with the broadcasting contribution: You must never react to these messages
Fraud with the broadcasting contribution: You must never react to these messages
Google users have to be careful: if you receive this message, you will threaten danger
Google users have to be careful: if you receive this message, you will threaten danger
Always brazen: When you get this call, better put on immediately
Always brazen: When you get this call, better put on immediately
PayPal customers in the sight of fraudsters: How to expose the fake emails
PayPal customers in the sight of fraudsters: How to expose the fake emails
Via Darknet scanners such as "Have i Been Pwned", users can check whether they are affected by data leaks-in the current case around PayPal, this does not yet exist.The founder of the tool is now also expressed.
The links marked with a symbol are affiliate links.If you are purchased, we will receive a commission for you at no additional cost.The editorial selection and evaluation of the products remains unaffected.Your click helps to finance our free offer.
In a Darknet forum, user “Chucky_BF” claims to have come to 15.6 million PayPal access data, including email addresses and unencrypted passwords.
As with past data leaks, many users are currently flocking to platforms such as "Have I Been Pwned" (HIBP) or the Identity Leak Checker from the German Hasso-Plattner Institute.
These tools check whether your own email is affected by known data leaks.It has therefore also recommended chip in connection with the current incident.
As Pwned founder and CEO Troy Hunt informed us on request, the tool in the current, unconfirmed case around PayPal cannot (yet) help:
ADVERTISEMENT
I Haven’t Seen the Data Yet But Given It Didn’t Come from PayPal and Doesn’t Pose Any New Risk, it may not be suitible for Hibp.I’ll have to review it if it ever turns up publicly.
Translation: I have not yet seen the data, but since they do not come from PayPal and do not represent a new risk, they may not be suitable for HIBP.I will check them if they ever become publicly accessible.
In a Darknet forum, user wants to sell "chucky_bf" 1.1 GB on PayPal user fos at a price of $ 750.Screenshot
"Have I Been Pwned" CEO on the possible PayPal data leak, as the cyber security expert confirmed to us, the presumably leaked data record with PayPal user fos is currently not yet taken into account by have I be pwned, since no risk is currently going.However, this could change if the data should be made publicly accessible.
ADVERTISEMENT
In a post on X (Twitter), Hunt also rules out that the stolen data comes directly from PayPal, since no passwords are stored in plain language.As he suspects, they were stolen via other paths, for example via malware.It is also conceivable that the anonymous Darknet-poster is simply lying and there is no leak.PayPal has not yet confirmed that user data has been stolen.
Chip has also asked the Hasso Plattner Institute whether the HPI Identity Leak Checker offered into account the data leak.One answer is still pending, we will update the article if necessary.
ADVERTISEMENT
What users can do now, even if the online services should give the all-clear in your email address: If you want to be on the safe side, you should change the password to your PayPal account as a precaution.Note the most important rules for strong passwords and do not use it on any other platform.
Other important precautions that you can also carry out regardless of the current case: