PayPal Tens of Millions of Accounts Leaked

Estimated read time 2 min read

Recently, an internet hacker under the name “Chucky_BF” on the dark web forum claimed to be selling a data set called “Global PayPal Credential Dump 2025”. According to the description, the data set contains over 15.8 million records, including email addresses, plain text passwords, and URLs related to PayPal services.

Screenshot

The overall file size is about 1.1GB, and the selling price is $750. In the samples provided by the hacker, combinations of email addresses such as Gmail and passwords can be seen, which directly link to the login pages of PayPal’s web and mobile versions. Some accounts appear in both the Web and App versions, indicating that the data collection method involves different platforms. Industry analysis suggests that this data did not come from a direct breach of the PayPal system, but is more likely to be a collection of credentials stolen by information-stealing malware (Infostealer) from infected devices. This type of malicious program usually collects login information and related activities saved in the browser and then packages them for sale on the black market. At present, the authenticity of this data set cannot be confirmed, and it may contain a mixture of real and fake accounts. PayPal has not yet issued a public response to this incident.

More From Author

1 Comment

Add yours

+ Leave a Comment