Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

New York’s financial regulator documented a PayPal credential-stuffing incident from December 2022 in an enforcement order issued in 2025. It was not a new 2026 warning: the order says attackers used stolen login details to access exposed information in online tax forms. Here’s what happened and how to reduce the risk to your account.

Did PayPal warn users about credential stuffing?

The clearest public record is a 2025 consent order from the New York State Department of Financial Services (DFS), concerning a PayPal security event in December 2022. It describes an attack involving credential stuffing, not a separate recent PayPal warning specifically about that threat. Read the DFS consent order.

What happened in the 2022 incident

On December 6, 2022, a PayPal security analyst found an online message describing a way to view customers’ Social Security numbers. PayPal discovered that some online Form 1099-K documents contained unmasked names, dates of birth, and full Social Security numbers. The next day, PayPal detected a spike in attempts to access its platform and concluded that attackers were using credential stuffing to reach the exposed information.

DFS says the event affected tens of thousands of consumers, but the reviewed order does not give an exact count. That figure describes affected consumers; it is not a count of confirmed losses.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How PayPal responded and what DFS found

PayPal added CAPTCHA and rate limiting, which DFS says stopped the automated account access. It masked the exposed information and forced password resets for affected accounts. DFS also found shortcomings in how PayPal applied cybersecurity policies, trained and oversaw engineering staff, and protected nonpublic information. The customer accounts accessed during the event did not require multi-factor authentication (MFA).

The 2025 order imposed a $2 million civil monetary penalty. It also records PayPal’s remediation, including clarifying policies, training staff, improving production-code monitoring, and requiring MFA for all US customer account logins. The penalty is a regulatory fine, not an estimate of consumer losses.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What is credential stuffing?

Credential stuffing is an automated attempt to sign in using username-and-password combinations obtained from another source, such as a data breach. It succeeds when people reuse the same credentials across services: a password exposed elsewhere may then unlock a PayPal account.

It differs from brute-force guessing. Credential stuffing tests stolen credential pairs; brute-force attacks systematically try to guess passwords. Automated attempts may be paced to evade simple restrictions on unsuccessful logins, as the Federal Trade Commission (FTC) explains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How do I protect my PayPal account?

Use a unique password

Give PayPal a password you do not use anywhere else. PayPal recommends at least 12 characters and suggests a passphrase of three or more words; avoid common words and personal details. A distinct password limits the damage if another service exposes your credentials.

Use a password manager if it helps

A password manager can create and store separate passwords so you do not have to memorize each one. PayPal says password-manager apps can store and sync passwords. Protect the manager with a strong, unique master passphrase.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Turn on 2-step verification

PayPal’s US security guidance describes setting up 2-step verification with an authenticator app or SMS. If available to you, the FTC recommends an authenticator app or security key over SMS or email; SMS can be vulnerable to SIM-swap attacks. PayPal’s US instructions document authenticator-app and SMS setup, while its passkey option is device-based—do not assume a standalone security key is supported for PayPal login. Never share a verification code: PayPal says it will not ask for one by phone, email, or text.

Consider a passkey on an eligible device

PayPal passkeys use your device’s biometrics, PIN, or unlock credential instead of a conventional password. Eligibility depends on the account and the device, operating system, and browser. Check PayPal’s current US account-security instructions for setup and compatibility.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should I do if I get a PayPal password reset message?

Do not click a reset link in an unsolicited message. Open a browser and type PayPal’s address yourself, or open the PayPal app, then sign in and check your account. Do not reply with your password or a verification code. A message that urges immediate action is not proof that it came from PayPal.

What should I do if I see unusual PayPal activity?

  1. Change your password. Sign in through PayPal’s official website or app, not through a link in an unexpected message, and set a unique password.
  2. Review your account activity. Look for transactions or account changes you do not recognize.
  3. Contact PayPal through its site or app. Use its official channels to report suspected unauthorized access or fraud; PayPal directs users to its Security Center to report suspicious messages.
  4. Contact your card issuer about an unfamiliar card alert. PayPal advises contacting the issuer if you do not recognize an unusual card alert.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.