PayPal fined by New York for cybersecurity failures

Published 01/23/2025, 09:45 AM
Updated 01/23/2025, 12:16 PM
© Reuters. FILE PHOTO: The PayPal logo is seen at an office building in Berlin, Germany, March 5, 2019.   REUTERS/Fabrizio Bensch/File Photo
PYPL
-

By Jonathan Stempel

NEW YORK (Reuters) -PayPal will pay a $2 million civil fine over cybersecurity failures that led to the exposure of customers' Social Security numbers in late 2022, New York state's Department of Financial Services said on Thursday.

Adrienne Harris, New York's financial services superintendent, said a probe by her office found PayPal (NASDAQ:PYPL) failed to use qualified staff to manage key cybersecurity functions or provide adequate training to address cybersecurity risks.

This left names, dates of birth and Social Security numbers belonging to customers of the San Jose, California-based digital payments company easily accessible to cybercriminals for about seven weeks, she said.

PayPal cooperated with the probe. "Protecting consumers' personal information and maintaining a secure platform is a top priority for us and we take our regulatory responsibilities seriously," the company said in a statement.

According to a consent order, PayPal discovered the problem after a security analyst on Dec. 6, 2022 read an online message that said "PP EXPLOIT TO GET SSN."

The next day, PayPal's cybersecurity team saw a spike in attempts to access its online platform, and determined that cybercriminals were using "credential stuffing" to view federal tax forms for tens of thousands of customers.

Data were exposed after PayPal made changes to existing data flows so it could make the forms available to more customers.

Harris also faulted PayPal for not requiring customers to use multifactor authentication or controls such as CAPTCHA to prevent unauthorized access.

© Reuters. FILE PHOTO: The PayPal logo is seen at an office building in Berlin, Germany, March 5, 2019.   REUTERS/Fabrizio Bensch/File Photo

The fine was for violating the financial services department's cybersecurity regulation, adopted in 2017.

PayPal now requires multifactor authentication on all U.S. customer accounts, forced password resets on affected accounts, and has implemented CAPTCHA, the consent order said.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2025 - Fusion Media Limited. All Rights Reserved.