Article Details
PayPal data in the Darknet: Users should now consider this now
Published on August 21, 2025
Audio: Apparently data leak at PayPal payment service: What can customers do?(3 min) speaker
PayPal data in the Darknet: Users should now note: 21.08.2025 1:15 p.m. Cybercriminals could have millions of PayPal data.If these are up -to -date and real, there is immense damage.What should users of the payment service do now?
In the Darknet, a hacker offers a data package with 15.8 million access data for PayPal, including email addresses and passwords.It is unclear whether it is real user data and whether they can be used at PayPal.IT experts suspect that the data was not captured by a data leak at PayPal, but by malware.This, for example through phishing attacks on devices, takes up stored access data for online services.PayPal has not yet commented on the incident.
Criminals could use the captured data, including the address, date of birth or bank details, for targeted phishing attacks-for example, send an email that supposedly comes from PayPal and call up to enter additional sensitive data under a fake link.Simply transfer money is not possible with PayPal with email and password alone.
In addition, the thieves could systematically enter the passwords with further online services and try to gain access.If users use the same access data for several services, this method is particularly worthwhile.
Protect PayPal account
If you have a PayPal access, you should therefore be on the safe side and immediately protect your account with a few simple steps:
Change PayPal password: The new password should be a strong password with at least 12 characters with upper and small letters, numbers and special characters.Or you can use free password managers such as Keepass or Bitwarden to create a safe password and then use it automatically.The following also applies to this: A safe master password is mandatory.Important: The new password should be unique and not used in any other online service.
: The new password should be a strong password with at least 12 characters with large and small letters, numbers and special characters.Or you can use free password managers such as Keepass or Bitwarden to create a safe password and then use it automatically.The following also applies to this: A safe master password is mandatory.Important: The new password should be unique and not used in any other online service.Not an identical password: If you also use your previous PayPal password for other services, you should change it there immediately.
: If you also use your previous PayPal password for other services, you should change it there immediately.Set up two-factor authentication: With the two-factor authentication, you can also protect your account.The separate query - by SMS code, confirmation via the app or biometric approval by fingerprint or face - makes it much more difficult to get attackers.Therefore, you should activate the function for all important online services.With PayPal, this is in the security settings.
: With the two-factor authentication you can also protect your account.The separate query - by SMS code, confirmation via the app or biometric approval by fingerprint or face - makes it much more difficult to get attackers.Therefore, you should activate the function for all important online services.With PayPal, this is in the security settings.Keep an eye on emails and transactions: Users of PayPal should currently look particularly closely at emails that are said to come from PayPal.You should also observe your account activities, especially with regard to unusual transactions.This also applies to other online services.
: PayPal users should currently look particularly closely at emails that are said to come from PayPal.You should also observe your account activities, especially with regard to unusual transactions.This also applies to other online services.Pay attention to suspicious signs: Users should be particularly suspicious of these signs: unknown login activities and notifications of foreign devices, unauthorized payments and debits as well as changed account details and settings.
Via the internet service external link HavegePwned or the external link Identity-Leak-Checker from the Hasso-Plattner Institute, users can basically check whether your email address and other data have been stolen in the event of a hacker attack.This is not yet possible in the current case, but the services are updated regularly.
This topic in the program: NDR Info |Economy |21.08.2025 |07:43 a.m.