Archetyp Links

Dark Mode

Article Details

15.8 million passwords extracted with malware reach sale;If you have saved your password in your browser you may already be in the list

Published on August 18, 2025

A hacker known as Chucky_BF sells online a database with 15.8 million email addresses and passwords, allegedly associated with PayPal accounts.The information was reported by Hackread.com, which states that the file has 1.1 GB and is offered at the price of $ 750.Data sets also include links to sites where the credentials would have been used, which raises the risk of attacks such as phishing or fraudulent access to accounts. According to the Troy Hunt security expert, this is not a direct hack on Paypal.The platform does not store passwords clearly, so the data seem to have been collected from users' devices, most likely by infostealer malware.This type of software is distributed by infected discharges, trap emails or compromised sites, and extracts the passwords saved to the browser or other applications. It is not clear how many of the data sold are valid.Even so, the risk is serious, especially for those who use the same password on several sites.Specialists recommend changing password and activating two steps (2FA), whether you use PayPal often or occasionally.It is one of the simplest protective measures in front of this type of attack. Paypal has not issued any official reaction so far.In the context in which the platform processes millions of transactions daily for over 400 million accounts, any incident - even indirectly - has the potential to affect the confidence of users.In recent months, the company has been criticized for other issues, including Steam limitations and Google Wallet rupture.