Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If you think your PayPal account may be compromised, secure it now, then check whether the activity was truly unauthorized. Go to PayPal by typing paypal.com into your browser or opening the official app—not through a link in a message. Change your password, check account details and recent activity, and protect the email, bank, or card accounts connected to PayPal.

Signs your PayPal account may be compromised

One strange-looking charge does not prove someone accessed your account. Look for a combination of signs that you did not initiate or approve:

  • Your password, email address, phone number, security settings, or mailing address changed without your permission.
  • You received a login alert for a device or location you do not recognize.
  • There are payments, transfers, withdrawals, refunds, or new payment methods you did not authorize.
  • Messages appear to have been sent from your PayPal account that you did not write.
  • You cannot sign in with the correct credentials, or you see repeated attempts to add or use a card.

The FTC lists unexpected changes to account information, unfamiliar login alerts, and inability to sign in among common signs of account takeover. FTC guidance on hacked accounts can help you assess other affected accounts, too.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do right away

  1. Stop using links in suspicious messages. Open PayPal independently. PayPal recommends typing its address into a new browser window rather than following a password-reset or payment link in an email or text. A message asking for your password or authentication code, pressuring you to act immediately, or telling you to call a number it supplies may be a phishing attempt. PayPal says it will not ask for your password or authentication code by phone, email, or text. See its account-protection guidance.
  2. Change your PayPal password. Sign in through PayPal’s official website or app and set a long, unique password. PayPal suggests at least 12 characters and advises against reusing passwords. If you used the old password elsewhere, change it on those accounts as well, especially your email account.
  3. Update security questions and inspect account details. Check primary and secondary email addresses, phone numbers, mailing and billing addresses, linked banks and cards, shipping addresses, and saved merchants. Remove or correct anything you did not add. PayPal advises changing security questions after suspected account compromise; its guidance for suspected fraud or unauthorized activity explains its reporting options.
  4. Turn on two-step verification. In PayPal’s U.S. website instructions, sign in, select the Settings gear, choose Security, then select Set Up under 2-step verification. Choose an available method, such as an authenticator app or SMS, and follow the enrollment prompts. PayPal’s exact options can vary by account, device, country, and interface. Never share the code with another person.
  5. Review recent activity and automatic payments. Check transactions, subscriptions, saved businesses, and automatic payments for unfamiliar activity. If you find an unauthorized payment, report it through the Resolution Center using the steps below.
  6. Secure the email account tied to PayPal. Change its password from the provider’s official site, enable two-factor authentication, review recent sign-ins and recovery details, and look for unfamiliar forwarding rules or filters. If the PayPal password was reused on other accounts, change it there, too.
  7. Contact your bank or card issuer if its account may be affected. Use the phone number on your card or statement, or the institution’s official app. PayPal’s dispute process does not replace reporting unauthorized activity in a linked bank or card account.

Two-step verification improves account protection, but it cannot eliminate risks such as phishing, malware, a compromised email account, or a SIM swap.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Check whether an unfamiliar charge is actually unauthorized

Before reporting a payment as unauthorized, check whether it could be an automatic payment, a purchase by a household member or other authorized user, or a merchant charge with a different billing name. Also check whether it is pending rather than completed, or related to a refund, reversal, currency conversion, temporary card verification, marketplace, or app purchase.

PayPal specifically advises checking family-member activity and automatic payments before filing an unauthorized-activity report. Its instructions for reporting unauthorized activity also describe how to review automatic payments. Menu labels vary, but the website may show them under Settings → Payments → Subscriptions and saved businesses or Automatic Payments. Select a merchant to review or cancel future automatic payments where available. Canceling a payment authorization does not necessarily reverse a completed charge; you may need to contact the merchant or file the appropriate PayPal dispute.

A pending authorization, completed payment, bank transfer, PayPal Credit transaction, and card transaction processed outside PayPal can have different cancellation and reporting options. Do not assume PayPal can cancel every payment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Report a payment you did not authorize

  1. Open PayPal’s Resolution Center.
  2. Select Report a problem.
  3. Choose the suspicious payment and select Continue.
  4. Choose I want to report unauthorized activity and follow the prompts.
  5. Keep the confirmation and case number.

These are the reported steps for PayPal’s U.S. website; labels can vary by interface or account. PayPal says it will email you within 10 days after you file, but that is not a guaranteed deadline for a final decision or refund. PayPal investigates reported activity, and the outcome depends on the facts and applicable terms.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Save the transaction date and amount, merchant or recipient name, PayPal transaction ID, screenshots, messages, account changes you noticed, and the date you first contacted PayPal. Keep the case number and correspondence. PayPal’s fraud-reporting page lists reporting routes for different account and payment products.

An unauthorized-payment report is not necessarily the right route for a purchase you made but did not receive, a merchant billing problem, or a subscription you want to cancel. Choose the issue that matches what happened.

If you cannot sign in

Use account recovery or Contact Us from PayPal’s own website. Do not call a number from an unsolicited message, search ad, or unverified search result, and do not install remote-access software for someone claiming to be PayPal support. A legitimate support interaction should not require you to reveal your password or one-time authentication code. PayPal’s official contact page provides support categories.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PayPal may ask you to verify your identity through a text, phone call, account information, security questions, card details, email, or push notification. Its guidance says repeated unsuccessful security checks can mean waiting 24 hours before trying again or contacting PayPal directly. If the phone number on the account has changed or codes go to an old number, use PayPal’s recovery route to regain access and update the number; see PayPal’s help for a changed mobile number and its security-check guidance.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

If an attacker changed your email or phone number, treat the account as taken over. Stop guessing passwords, contact PayPal through its official recovery route, and secure the affected email account and mobile number at the same time.

Protect linked financial accounts, your phone, and your email

Bank accounts and cards

Call the bank or card issuer promptly if its statement shows an unauthorized transaction, the attacker may have obtained the full account or card details, or you see unfamiliar transfers or repeated attempts to add or use a card. Use the number on the card or statement or the institution’s official app. PayPal advises contacting the card issuer if it alerts you to multiple unusual attempts to use or add a card; see PayPal’s unusual-activity guidance. Report activity involving a PayPal Credit account or PayPal-branded card through the relevant product’s official reporting route as well.

Email and other online accounts

Your email account matters because it may receive password-reset links and security alerts. Change its password, turn on two-factor authentication, review sign-ins and recovery email addresses or phone numbers, remove unfamiliar recovery options, and inspect forwarding rules, filters, sent mail, and deleted mail. The FTC recommends these recovery checks in its account recovery guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Phone and device

If text verification suddenly stops working or you lose control of your phone number, contact your mobile carrier to check for a SIM swap or account takeover. If you downloaded a file, installed software, or added a suspicious browser extension after following a message, update your security software and scan the device. When you suspect malware, change passwords from a clean device; the FTC’s recovery advice also recommends updating security software and scanning.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to consider an identity-theft report or credit freeze

A PayPal password compromise alone does not automatically mean someone can open credit in your name. If Social Security, identity-document, or other sensitive personal information may have been exposed, report identity theft at IdentityTheft.gov for an FTC recovery plan and consider credit-bureau protections.

Situation Practical next step
You received a suspicious PayPal email or text but see no account changes Check PayPal directly, do not click the message, and report it through PayPal’s official security or support tools.
Your PayPal password may have been exposed Change it, change any reused passwords, enable two-step verification, and inspect account recovery details and recent activity.
You find an unauthorized PayPal payment Secure the account and report the payment through the Resolution Center.
A linked bank or card account also shows unauthorized activity Contact the bank or issuer promptly through its official channel.
Your email account is compromised Secure the email account and its recovery settings, then regain or protect PayPal access.
Your Social Security number or identity documents may have been exposed Use IdentityTheft.gov and consider a fraud alert or credit freeze.

For U.S. consumers, an initial fraud alert is free, lasts one year, and can be requested from one of the three nationwide credit bureaus; that bureau must notify the other two. A credit freeze is free, available to anyone, and must be placed separately with Equifax, Experian, and TransUnion; it remains until lifted or removed. An extended fraud alert can last seven years for confirmed identity-theft victims with an FTC Identity Theft Report. The FTC explains the differences in its fraud-alert and credit-freeze guide and credit-freeze details. A freeze restricts access to your credit report for opening new credit; it does not secure an existing PayPal login or reverse a payment.

If you clicked a phishing link but see no suspicious activity

Clicking a link does not prove your account was accessed, but entering your password or a verification code may have exposed it. Change the PayPal password, replace any reused passwords, enable two-step verification, check recent activity and account details, and report the suspicious message through PayPal’s official tools. If the link led you to download or install something, scan the device and change passwords from a clean device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not use a sender name, logo, or display address alone to decide that a message is genuine. PayPal says legitimate emails include the full name or business name shown on the account, but that detail is not a complete test because message details and branding can be forged. Inspect the account by opening PayPal directly.

What not to do

  • Do not click suspicious account, refund, payment, or password-reset links.
  • Do not call a number supplied in an unsolicited message or give anyone your password or one-time code.
  • Do not install remote-access software or send money to “secure,” “verify,” or “unlock” an account.
  • Do not delete screenshots, transaction details, or correspondence before saving them.
  • Do not treat every unfamiliar merchant name as fraud, or wait for a PayPal dispute to address a compromised bank or card account.
  • Do not reuse your replacement password on other accounts.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.