Saturday, May 31, 2025

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » PayPal Breach 2023: Tip of the Iceberg

SBN

PayPal Breach 2023: Tip of the Iceberg

by Steve Tout on January 24, 2023

Here we go again! Last month it was LastPass. Prior to that it was Uber. Before that, Okta. And before that, well… you know where this is going. Now the PayPal Breach 2023, 35,000 customers have been breached by a credential stuffing attack, according to PayPal officials.

It is bad enough that some 35,000 PayPal customers were impacted by a preventable cyberattack method; the troubling part is that 35k customers are a small percent of PayPal’s 429 million active accounts, which are no doubt being targeted by credential stuffing attacks as you read this. My question is, what are PayPal officials going to do to protect 429 million accounts from future attacks?

The thing about credential stuffing attacks is that it is a predictable playbook used by cybercriminals that often has a high probability of success.  Cybersecurity experts who advise implementing 2FA “everywhere” and using long, complex passwords do a disservice and miss an opportunity to recommend solutions that may actually work.

Techstrong Gang Youtube
AWS Hub

If 2FA is so good…

Whenever another major data breach lands in a headline, I can predict not only the narrative about root cause, but also about the efforts taken to soothe customers and recommendations to protect against future credential-stuffing attacks. Enable 2FA/MFA, the recommendations read. Don’t get me wrong, MFA security is an excellent choice for enhanced account security and protection against common attack scenarios. But as Microsoft reported in its 2022 Cyber Signals report, the adoption rate is 22% among enterprise users, and the benefit of 2FA/MFA isn’t realized unless it is implemented.

Another challenge with 2FA/MFA is that it can be susceptible to MFA fatigue and MFA bypass attacks, as we learned from the Okta breach. Even when customers and employees do “the right thing” by enabling their MFA, we can learn from history that MFA alone is not enough.

Until CISOs and organizations require 2FA/MFA by default, it will not be an effective defense against the kinds of attacks that occurred in the PayPal breach. The 2FA/MFA lifestyle is a hard one to adopt at scale, and CISOs should consider solutions to enable stronger authentication that doesn’t rely on discipline and lifestyle changes of end users.

The PayPal breach of 2023 reminds us that 2FA isn’t a silver bullet and that credential security matters more than ever.

Protection begins with a better credential security model

The lack of disciplined adoption of 2FA/MFA forces CISOs and organizations to consider alternatives. Using a Zero Trust mindset may lead us toward a passwordless future, or it may lead us to think more strategically about improving our credential security models. The bad news for credentials is that over 30 billion stolen passwords are floating around on the dark web and various hacker forums. The good news is that more than 30 billion stolen passwords are floating around on the dark web, which becomes a source of intelligence that informs and enables stronger authentication.

VeriClouds patented CredVerify technology is an identity threat intelligence platform that can block stolen credentials from being used during login by providing visibility, rapid detection, and automated remediation. Through real-time checks against credential threat intelligence, identity providers and organizations can enforce strong authentication and identity assurance across SaaS and on-premises environments with standard restful API integrations and solution accelerators. This approach complements existing MFA investments and ensures that stolen credentials are not used as a weapon during account takeover or credential stuffing attacks.

VeriClouds patented CredVerify technology provides:

  • Comprehensive visibility into the risk of compromised credentials
  • Enhanced credential security for the user management lifecycle
  • Continuous monitoring and detection of compromised credentials for the entire organization (user and org level)
  • Secure credential verification with k-anonymity protection

The PayPal breach of 2023 reminds us that 2FA isn’t a silver bullet and that credential security matters more than ever.

If you haven’t done so, you can request a demo or get started with credential verification for protecting your sensitive data and customer accounts.

VeriClouds is the white-labeled solution behind one of the largest email providers in the world.

Download the Datasheet

See Identity Threat Detection & Response in Action

Talk to Sales

The post PayPal Breach 2023: Tip of the Iceberg appeared first on VeriClouds.

*** This is a Security Bloggers Network syndicated blog from Blog – VeriClouds authored by Steve Tout. Read the original post at: https://www.vericlouds.com/paypal-breach-2023-tip-of-the-iceberg/

January 24, 2023January 24, 2023 Steve Tout 2fa, Account Takeover Attacks, CredVerify, exposed data, leaked passwords
  • ← What is an SBOM and Why is it Valuable? 
  • Why you should never trust PoC exploits on GitHub →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Security Field Day

Upcoming Webinars

How to Spot and Stop Security Risks From Unmanaged AI Tools
Software Supply Chain Security: Navigating NIST, CRA, and FDA Regulations

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

RSA and Bitcoin at BIG Risk from Quantum Compute
Unsophisticated Actors, Poor Hygiene Prompt CI Alert for Oil & Gas 
Understanding the Importance of Incident Response Plans for Nonprofits
Victoria’s Secret Hit By ‘Security Incident’ After Attacks on UK Retailers
FTC Orders GoDaddy to Bolster its Security After Years of Attacks
Massive Data Breach Exposes 184 Million Login Credentials
Building a Secure LLM Gateway (and an MCP Server) with GitGuardian & AWS Lambda
Google Boosts LiteRT and Gemini Nano for On-Device AI Efficiency
Cisco Unveils JARVIS: AI Assistant Transforming Platform Engineering
Coinbase Hit with Lawsuit Over $400M Data Breach and Stock Loss

Industry Spotlight

USDA Worker, 5 Others Charged in Food Stamp Fraud Operation
Cyberlaw Cybersecurity Data Security Featured Governance, Risk & Compliance Identity & Access Industry Spotlight News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

USDA Worker, 5 Others Charged in Food Stamp Fraud Operation

May 30, 2025 Jeffrey Burt | Yesterday 0
Victoria’s Secret Hit By ‘Security Incident’ After Attacks on UK Retailers
Cloud Security Cybersecurity Data Security Featured Incident Response Industry Spotlight Malware Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Victoria’s Secret Hit By ‘Security Incident’ After Attacks on UK Retailers

May 29, 2025 Jeffrey Burt | 1 day ago 0
Microsoft Opens Windows Update to 3rd-Party Apps
Application Security Cybersecurity Data Privacy Data Security DevOps Endpoint Featured Governance, Risk & Compliance Humor Incident Response Industry Spotlight Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Microsoft Opens Windows Update to 3rd-Party Apps

May 29, 2025 Richi Jennings | 1 day ago 0

Top Stories

SentinelOne Outage Leaves Security Teams Hanging for Six Hours
Cloud Security Cybersecurity Data Security Featured Governance, Risk & Compliance Incident Response Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence 

SentinelOne Outage Leaves Security Teams Hanging for Six Hours

May 30, 2025 Jeffrey Burt | Yesterday 0
Zscaler Moves to Acquire Red Canary MDR Service
Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Zscaler Moves to Acquire Red Canary MDR Service

May 30, 2025 Michael Vizard | Yesterday 0
FTC Orders GoDaddy to Bolster its Security After Years of Attacks
Application Security Cloud Security Cybersecurity Data Privacy Data Security Featured Governance, Risk & Compliance Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

FTC Orders GoDaddy to Bolster its Security After Years of Attacks

May 28, 2025 Jeffrey Burt | 2 days ago 0

Security Humor

Orange Open Sign on Window

Microsoft Opens Windows Update to 3rd-Party Apps

Download Free eBook

The State of Cloud Native Security 2020

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2025 Techstrong Group Inc. All rights reserved.
×

Security in AI

Step 1 of 7

14%
How would you best describe your organization's current stage of securing the use of generative AI in your applications?(Required)
Have you implemented, or are you planning to implement, zero trust security for the AI your organization uses or develops?(Required)
What are the three biggest challenges your organization faces when integrating generative AI into applications or workflows? (Select up to three)(Required)
How does your organization secure proprietary information used in AI training, tuning, or retrieval-augmented generation (RAG)? (Select all that apply)(Required)
Which of the following kinds of tools are you currently using to secure your organization’s use of generative AI? (select all that apply)(Required)
How valuable do you think it would it be to have a solution that classifies and quantifies risks associated with generative AI tools?(Required)
What are, or do you think would be, the most important reasons for implementing generative AI security measures? (Select up to three)(Required)

×