Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: PayPal Fined $2 Million Over 2022 Breach of Customer Accounts
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > World Tech > PayPal Fined $2 Million Over 2022 Breach of Customer Accounts
World Tech

PayPal Fined $2 Million Over 2022 Breach of Customer Accounts

The New York State Department of Financial Services (DFS) has fined PayPal $2 million to settle claims of cybersecurity failures that led to a data breach in 2022, exposing some customers' Social Security numbers. The payment gateway did not properly adopt and maintain access control, customer data, and identity management policies.

Matthew Giannelis
Last updated: January 27, 2025 9:50 pm
Matthew Giannelis
Share
SHARE

The New York State Department of Financial Services (DFS) has instructed PayPal to pay $2 million to settle charges related to cybersecurity issues that caused a data breach in 2022.

The breach resulted in the exposure of sensitive customer information, including some individuals’ Social Security numbers and comes as part of ongoing efforts to hold companies accountable for protecting user data and addressing security lapses.

According to New York DFS which also noted PayPal’s lack of multi-factor authentication mandates during the time of the breach it did not properly adopt and maintain access control, customer data, and identity management policies.

“New York’s nation-leading cybersecurity regulation sets a critical standard for safeguarding consumer data and strengthening the resilience of financial institutions,” said Adrienne Harris, superintendent of DFS.

“Qualified cybersecurity personnel are the first line of defense against potential data breaches, and providing proper training and effectively implementing cybersecurity policies and procedures are vital steps to protecting sensitive data and mitigating risks.” Harris said.

For about seven weeks, sensitive customer data, including names, birthdates, and Social Security numbers, was left exposed to cybercriminals due to a security lapse at PayPal, a digital payments company based in San Jose, California.

The breach was uncovered after a security analyst came across an online message on December 6, 2022, reading “PP EXPLOIT TO GET SSN.”

The following day, PayPal’s cybersecurity team noticed a significant increase in unauthorized attempts to access its platform. They determined that cybercriminals were using “credential stuffing” attacks to access federal tax forms for tens of thousands of customers.

The data became exposed when PayPal made changes to its data flow processes to provide easier access to the forms for more customers.

The New York State Department of Financial Services (DFS) criticized PayPal for failing to implement adequate security measures, such as multifactor authentication or CAPTCHA, to prevent unauthorized access.

“Protecting consumers’ personal information and maintaining a secure platform is a top priority for us, and we take our regulatory responsibilities seriously,” the company said in a statement.

In response to the breach, PayPal is now requiring multifactor authentication, forcing password resets on affected accounts, and adding CAPTCHA for enhanced security. The fine was for violating the DFS’s 2017 cybersecurity regulation.

ByMatthew Giannelis
Follow:
Secondary editor and executive officer at Tech Business News. An IT support engineer for 20 years he's also an advocate for cyber security and anti-spam laws.
Previous Article Mitigating Threats To Cloud-Based GPUs Mitigating Threats To Cloud-Based GPUs
Next Article NSW Health appoints new chief information officer Richard Taggart following a six-month search. NSW Health Appoints Richard Taggart As New Chief Information Officer (CIO)
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

PayPal fined by New York - cybersecurity failures

Tech Articles

AI Is Forcing Developers To Abandon Untyped Code

Why AI Is Forcing Developers To Abandon Untyped Code

AI has made ambiguity a liability, with developers spending over…

January 13, 2026
How Telstra Held Back Australia’s Internet Speed — And What It Means for Users

How Telstra Held Back Australia’s Internet Speed — And What It Means for Users

How Telstra Held Back Australia’s Internet Speed — And What…

January 21, 2026
Chatbots Condemning Children To Antisocial Behaviour?

Are Chatbots Condemning Children To Antisocial Behaviour?

Are Chatbots Condemning Children To Antisocial Behaviour? Not by default…

March 2, 2026

Recent News

Twitter Privacy
Global

Twitter reviews controversial new privacy policy

2 Min Read
Preventing network failures could save Singapore businesses billions
World Tech

Network Failures Costing Singapore Businesses Billions

4 Min Read
Threads Becomes Twitters Biggest Threat
World Tech

Meta’s New Social Media App, Threads Becomes Twitter’s Biggest Threat

9 Min Read
Submersible Vessel, Titan - imploded Titanic $30 video game comtroller
World Tech

Submersible Vessel, Titan Controlled By A $30 Video Game Controller When It Imploded.

6 Min Read
Tech News

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.


Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.


Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

April, 04, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?