Louise Pentland Paypal
(Image source: Doiy, 2018)
One-sentence summary:
A mass credential stuffing attack against Paypal users in December 2022 results in an almost 35,000-user data breach and a class action lawsuit.
Who was involved?
Paypal, almost 35,000 Paypal users, and a threat actor.
What was the timeline?
December 6, 2022: Breach starts
December 8, 2022: Breach ends, Paypal eliminates access of unauthorized third parties
December 20, 2022: Breach investigation concluded
January 18, 2023: Paypal notifies affected users via letters as well as state offices (e.g., Maine)
March 2, 2023: Class action lawsuit is filed against Paypal in the Northern District of California
What occurred?
In December 2022, a threat actor or group of threat actors performed a mass credential stuffing attack against Paypal allowing the successful breach of almost 35,000 user accounts (Gesser, 2023). The breach ended in only two days, however, the potential data breached included: “name, address, Social Security number, individual tax identification number, and/or date of birth” (Paypal, 2023, p. 1). Paypal notified users the next month and now faces a class action lawsuit for the incident (Donkor, 2023, p. 2; Pillard et al v. PayPal, 2023).
Estimated costs:
Equifax Two-year identity and credit monitoring. “Outside counsel” (Donkor, 2023, p. 1). Breach notification. Litigation defense.
Involved laws:
Federal Trade Commission Act, 15 U.S.C. § 45
State laws: Maine: 10 M.R.S.A. § 1346
California: CCPA and Cal. Civ. Code § 1798.29(a)
Nebraska Consumer Protection Act, Neb. Rev. Stat. § 59-1601, et seq.
Nebraska Uniform Deceptive Trade Practices Act, Neb. Rev. Stat. § 87-301, et seq.
Texas Deceptive Trade Practices—Consumer Protect Act, Tex. Bus. & Com. Code § 17.46(b)
Read more about the legal allegations in the lawsuit here: Pillard et al v. PayPal, Inc., Docket No. 5:23-cv-00936 (N.D. Cal. Mar 02, 2023), Court Docket
Root cause:
Credential stuffing enabled valid account access (Donkor, 2023, p. 1). Potential social engineering attacks or external breaches were used to obtain the credentials beforehand (external to Paypal) (Donkor, 2023, p. 1).
Lessons learned:
Rate limiting, lockout policies, strong password policies, conditional access (e.g., geographical, IP, or CTI-based) policies, risk-based authentication, attribute-based access control (ABAC), mandatory 2FA, FIDO authentication, breach-checking/breach warning password manager.
Sources:
Doiy, J. (2018, September). Louise-Pentland-Article-201809281401.jpg. law.com. https://images.law.com/contrib/content/uploads/sites/390/2018/09/Louise-Pentland-Article-201809281401.jpg
Donkor, A. (2023). BY ONLINE SUBMISSION. In Office of the Maine Attorney General. Office of the Maine Attorney General. Retrieved March 6, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06/68d53bbc-4a55-41f8-ad20-2831191f37f7/document.html
Gesser, A. (2023, January 18). Office of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches. Office of the Maine Attorney General. Retrieved March 6, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06.shtml
Paypal. (2023). NOTICE OF SECURITY INCIDENT. In Office of the Maine Attorney General. Office of the Maine Attorney General. Retrieved March 6, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06/60edd0dc-c00d-4117-b63d-e809fd21e918/document.html
Pillard et al v. PayPal, Inc., Docket No. 5:23-cv-00936 (N.D. Cal. Mar 02, 2023). https://www.bloomberglaw.com/ms/public/desktop/document/PillardetalvPayPalIncDocketNo523cv00936NDCalMar022023CourtDocket/1
