Had my paypal account hacked

They do this more often than not by breaking into the email account first as that tends to be the easiest to crack, then just request a password reset and off you go.

You're lucky you could still get into your PayPal account. Usually when they're done spending your money they also change the security details.
 
my paypal login name *is* my e-mail address. so thats how he got that and my paypal password *was* the same as my e-mail address password. So once they got my paypal account, they got my e-mail as well

Of course from this it is highley possible that they did not breach paypal at all. They could have breached Gmail and as a matter of course cross checked to see if the Gmail accounts they had manage to obtain also had paypal accounts.

Since it is very common for people to use one password for everything it would stand to reason that they get themselves a whole bunch of gmail accounts and probably near half of them they will find paypal accounts using the same password.

As for the deleting of mail notification they could have done that straight away as they would have been forwarded to your phone the instant they were received.

I suppose I am lucky in that respect in this country because my paypal is direct linked to my bank account not a card and in this country you can recall any payment out of your bank account within 30 days of it being paid.
 
Last edited:
There is nothing wrong with the security of Paypal rather the reason your account has been accessed is due to bad security and choice of passwords.


how did they get my password

for gmail or paypal, in the first place though ? they didnt guess it. As ive already said, its long and alphanumeric. The only problem with my password is that i used the same strong password on both accounts.

Furthermore it appears to be some random person from switzerland, so the chances that they know my personal details is somewhat slim.

But the original question still remains, how did they get the password if they didnt hack it from somewhere ?
 
obtaining it is not hard they just use software that keeps trying passwords until it find one that locks.

I read a report about net security not that long ago and at that time the hackers were using software that could try 50 to 60 thousand passwords a second.

According to that report the average persons password for most things could be cracked inside of 8 hours.
 
I've had paypal messages, which I think are fakes, where the wrong name (not mine) has been addressed, mentioned security attack etc.
 
thats a common one they send you that message with a link to sign in and make changes or get more info.

The link looks genuine enough so people click it and sign in but they do not sign into paypal they get a clone site that looks just like paypal and as soon as they put in their details and click send get a page that says there is a problem and please try later, meanwhile the server has just logged the username and password.

Now they have your details.

I never click links within those types of mails I always manually go to the site the way I always have so that I know it's the right site
 
thats a common one they send you that message with a link to sign in and make changes or get more info.

The link looks genuine enough so people click it and sign in but they do not sign into paypal they get a clone site that looks just like paypal and as soon as they put in their details and click send get a page that says there is a problem and please try later, meanwhile the server has just logged the username and password.

Now they have your details.

I never click links within those types of mails I always manually go to the site the way I always have so that I know it's the right site

I'll highlight this as its well explained sensible advice. It may seem common sense but we've all had the wool pulled over our eyes at some point.
 
Back
Top Bottom