Latest News

PayPal fined by New York for cybersecurity failures

PayPal will pay a. $ 2 million civil fine over cybersecurity failures that caused. the exposure of consumers' Social Security numbers in late 2022,. New York state's Department of Financial Services stated on. Thursday.

Adrienne Harris, New york city's monetary services. superintendent, said a probe by her office discovered PayPal stopped working. to utilize qualified personnel to handle key cybersecurity functions or. offer adequate training to attend to cybersecurity threats.

She said this left names, dates of birth and Social Security. numbers coming from consumers of the San Jose, California-based. digital payments business easily accessible to cybercriminals for. about seven weeks.

PayPal complied with the probe. It did not immediately. react to requests for remark.

According to an authorization order, PayPal found the problem. after a security expert on Dec. 6, 2022 read an online message. that stated PP EXPLOIT TO GET SSN.

The next day, PayPal's cybersecurity team saw a spike in. attempts to access its online platform, and figured out that. cybercriminals were using credential stuffing to view federal. tax return for 10s of countless customers.

Information were exposed after PayPal made modifications to existing information. flows so it could make the types offered to more consumers.

Harris likewise faulted PayPal for not needing consumers to. use multifactor authentication or controls such as CAPTCHA to. avoid unapproved access.

The fine was for violating the financial services. department's cybersecurity guideline, adopted in 2017.

PayPal has upgraded its security, consisting of by implementing. CAPTCHA, the consent order stated.

(source: Reuters)