Article Details
Mega data leak Hacker sells millions of PayPal logins-what you can do now
Published on August 21, 2025
The PayPal payment service is said to be affected by a large data leak.You should not panic, but you should take security measures immediately.Image: Sebastian Kahnert/dpa
Millions of PayPal logins are offered for sale in the Darknet.Experts are not sure how current the data is.With a few tricks you can protect yourself from bad surprises.
No time?Blue News summarized for you Hacker could have millions of PayPal data.
If the email addresses and passwords are real, the users of the payment service are threatened with immense damage.
If you use PayPal, you should immediately protect your account for security.Show more
It is a bargain: more than 15 million access data to PayPal accounts are currently available on the Internet.The user “Chucky_bf” only wants $ 750 for it.Good business for criminals: you could go shopping tour with the data.
MyTech: The digital hotspot for all Tech fans Blue News offers you insights from the Techwelt every day: news, backgrounds, tips and advice for your digital everyday life as well as tests and reviews on gadgets, tools and games.
The data record contains email addresses, passwords, URLs-all in plain language, reports the cybersecurity website "HackRead".It is unclear whether the data is real.IT expert Troy Hunt points out in a post at X that the data cannot come from PayPal directly, since the payment provider saves the passwords encrypted.A few years ago, Hunt founded the “Hvellenpwned” website: Here you can check whether your email address appears in data leaks.
🚨cyber Alert - PayPal‼ ️
Do you have a PayPal account?It Might Be Time to Change Your Password.
A threat actor using the alias "Chucky_bf" Claims to be selling 15.8 million email and plaintext password pairs linked to PayPal Accounts Worldwide.
The authenticity of this claim ... pic.twitter.com/orz9j1Besc - Hackmanac (@h4ckmanac) August 16, 2025
External content This content comes from external providers such as YouTube, Tiktok or Facebook.Please activate "Swisscom advertising at third parties" to display this content.Cookie settings
It is more likely that the data record was collected via phishing or malware attacks or compiled from older data leaks.This would also explain the discounter price.
Given passwords definite Didn’t come from PayPal in plain text, they’ve ether be obtained another way (info stealer, credential stuffing) or theree’s another explanation for this Claim 🤔 https://t.co/xmdyrafbhl - Troy Hunt (@troyhunt) August 16, 2025
External content This content comes from external providers such as YouTube, Tiktok or Facebook.Please activate "Swisscom advertising at third parties" to display this content.Cookie settings
Despite all doubts about the authenticity of the data, you should be careful.It cannot be ruled out that current and functioning combinations of email addresses and passwords can also be found in the collection.This is not one reason for the panic, but you should follow a few simple safety instructions: Last but not least, you are now a good opportunity to change your password at PayPal.
So you basically protect your PayPal account all your logins, regardless of current hacks and leaks, well.
Never use passwords several times!Fest for each online service - such as Instagram, Netflix, Ricardo or PayPal - of its own password.If you always use the same password, cybercriminals are enough hack to get access to all your services.
Activate the two-factor authentication, wherever possible!With the two-factor authentication (2FA), you have to enter a current code as a second stage according to the password or fingerprint scan so that you can log into an online service.These codes are often made available on your smartphone using an authentication app.Sometimes they also come by email or text message.If you use 2FA, cybercriminals don't get far with a pure email/password combination.
Choose a safe password!Use a random combination of large and small letters, numbers and special characters.A password length of 16 characters is considered safe.
Use a password manager!With these programs, numerous passwords for various internet services can be saved on the computer or smartphone.You can generate complex passwords that cannot be guessed simply on request.To access the database, users only need a master password - only you still have to remember this.Show more