Monday, June 15, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » PayPal Breach 2023: Tip of the Iceberg

SBN

PayPal Breach 2023: Tip of the Iceberg

by Steve Tout on January 24, 2023

Here we go again! Last month it was LastPass. Prior to that it was Uber. Before that, Okta. And before that, well… you know where this is going. Now the PayPal Breach 2023, 35,000 customers have been breached by a credential stuffing attack, according to PayPal officials.

It is bad enough that some 35,000 PayPal customers were impacted by a preventable cyberattack method; the troubling part is that 35k customers are a small percent of PayPal’s 429 million active accounts, which are no doubt being targeted by credential stuffing attacks as you read this. My question is, what are PayPal officials going to do to protect 429 million accounts from future attacks?

The thing about credential stuffing attacks is that it is a predictable playbook used by cybercriminals that often has a high probability of success.  Cybersecurity experts who advise implementing 2FA “everywhere” and using long, complex passwords do a disservice and miss an opportunity to recommend solutions that may actually work.

If 2FA is so good…

Whenever another major data breach lands in a headline, I can predict not only the narrative about root cause, but also about the efforts taken to soothe customers and recommendations to protect against future credential-stuffing attacks. Enable 2FA/MFA, the recommendations read. Don’t get me wrong, MFA security is an excellent choice for enhanced account security and protection against common attack scenarios. But as Microsoft reported in its 2022 Cyber Signals report, the adoption rate is 22% among enterprise users, and the benefit of 2FA/MFA isn’t realized unless it is implemented.

Another challenge with 2FA/MFA is that it can be susceptible to MFA fatigue and MFA bypass attacks, as we learned from the Okta breach. Even when customers and employees do “the right thing” by enabling their MFA, we can learn from history that MFA alone is not enough.

Until CISOs and organizations require 2FA/MFA by default, it will not be an effective defense against the kinds of attacks that occurred in the PayPal breach. The 2FA/MFA lifestyle is a hard one to adopt at scale, and CISOs should consider solutions to enable stronger authentication that doesn’t rely on discipline and lifestyle changes of end users.

The PayPal breach of 2023 reminds us that 2FA isn’t a silver bullet and that credential security matters more than ever.

Protection begins with a better credential security model

The lack of disciplined adoption of 2FA/MFA forces CISOs and organizations to consider alternatives. Using a Zero Trust mindset may lead us toward a passwordless future, or it may lead us to think more strategically about improving our credential security models. The bad news for credentials is that over 30 billion stolen passwords are floating around on the dark web and various hacker forums. The good news is that more than 30 billion stolen passwords are floating around on the dark web, which becomes a source of intelligence that informs and enables stronger authentication.

VeriClouds patented CredVerify technology is an identity threat intelligence platform that can block stolen credentials from being used during login by providing visibility, rapid detection, and automated remediation. Through real-time checks against credential threat intelligence, identity providers and organizations can enforce strong authentication and identity assurance across SaaS and on-premises environments with standard restful API integrations and solution accelerators. This approach complements existing MFA investments and ensures that stolen credentials are not used as a weapon during account takeover or credential stuffing attacks.

VeriClouds patented CredVerify technology provides:

  • Comprehensive visibility into the risk of compromised credentials
  • Enhanced credential security for the user management lifecycle
  • Continuous monitoring and detection of compromised credentials for the entire organization (user and org level)
  • Secure credential verification with k-anonymity protection

The PayPal breach of 2023 reminds us that 2FA isn’t a silver bullet and that credential security matters more than ever.

If you haven’t done so, you can request a demo or get started with credential verification for protecting your sensitive data and customer accounts.

VeriClouds is the white-labeled solution behind one of the largest email providers in the world.

Download the Datasheet

See Identity Threat Detection & Response in Action

Talk to Sales

The post PayPal Breach 2023: Tip of the Iceberg appeared first on VeriClouds.

*** This is a Security Bloggers Network syndicated blog from Blog – VeriClouds authored by Steve Tout. Read the original post at: https://www.vericlouds.com/paypal-breach-2023-tip-of-the-iceberg/

January 24, 2023January 24, 2023 Steve Tout 2fa, Account Takeover Attacks, CredVerify, exposed data, leaked passwords
  • ← What is an SBOM and Why is it Valuable? 
  • Why you should never trust PoC exploits on GitHub →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
The Cost of Exposure: Managing the Operational Risks of Executive Security Incidents
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

4 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Zscaler Launches Industry-First Zero Trust Security for Agentic AI
ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Oracle Issues Emergency Guidance as PeopleSoft Flaw Linked to Widespread Data Theft
Linux Kernel Bug Caused by Single Character Opens Path to Root Access
HackerOne Unveils Agentic AI Platform to Discover and Validate Vulnerabilities Faster
Atomic Arch npm Campaign Adds Malicious Dependency
ServiceNow Breach Explained: API Exposure, Risks & Security
Top 8 AI App Dev Platforms in 2026
CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
South Korea Fines Coupang $400M Over Data Breach Affecting Millions

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
Cloud Security Cybersecurity Data Privacy Data Security Endpoint Featured Identity & Access Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams

June 14, 2026 Jeffrey Burt | 12 hours ago 0
ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Incident Response Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Vulnerabilities 

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances

June 11, 2026 Jeffrey Burt | 4 days ago 0
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
AI and ML in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Zero-Trust 

Zscaler Launches Industry-First Zero Trust Security for Agentic AI

June 10, 2026 Jon Swartz | 4 days ago 0

Security Humor

Randall Munroe’s XKCD 'Soniferous Aether'

Randall Munroe’s XKCD ‘Soniferous Aether’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The State of Cloud Native Security 2020
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.