HomeSecurityPayPal: Hackers misused accounts and charged the owners

PayPal: Hackers hijacked accounts and charged the owners

According to reports, there is a bug in Google Pay, which some hackers and are exploiting to purchase products online and charge foreign PayPal accounts with unauthorized charges.

Since Friday, many users have been reporting that they are seeing strange transactions in their PayPal history, which are supposedly coming from their Google Pay account

Such reports appeared on multiple platforms, including PayPal forums , Reddit, Twitter, and the Russian and German forums Google Pay support

According to victims, hackers are exploiting Google Pay accounts to purchase products using their linked PayPal accounts. Screenshots that have been released and victims' testimonies show that most of the illegal transactions are taking place at US , and specifically at Target.

PayPal: Hackers hijacked accounts and charged the owners

Most of the victims appear to be German users.

The hackers have made purchases worth thousands of euros. Some transactions (from a single account) exceed €1,000.

The flaw exploited by the hackers has not yet been identified. PayPal said it is investigating. Google has not commented.

Yesterday, a German security researcher, Markus Fenske, claimed on Twitter that the current bug is similar to the one he and his colleague, Andreas Mayer, had informed PayPal about in February 2019. However, the service did not consider it a priority to fix it.

According to Fenske, the problem starts when you link your PayPal account to a Google Pay account. When the accounts are linked, PayPal creates a virtual card, with its own card number, expiration date, and CVC.

When a Google Pay user chooses to make a payment using funds from their PayPal account, the transaction is charged to this virtual card.

“If the virtual card were only for POS transactions, there would be no problem, but PayPal allows its use for online transactions,” the researcher said.

PayPal: Hackers hijacked accounts and charged the owners

Fenske believes that hackers have discovered the details of these virtual cards and are using them for unauthorized online.

Obtaining this information could be done through monitoring the phone/screen and malware infecting a device . Also, the attacker could guess the information.

“The attacker could do a brute-force attack, get the card number and the expiration date, which is about a year old,” Fenske said. “That narrows down the search.”.

“CVC doesn’t matter,” he added. “Everything is accepted.”

PayPal is investigating the case

Although Fenske was the first to announce the most likely cause of the attack, PayPal's security team began an investigation into the unauthorized transactions.

PayPal staff is reviewing all the data, including the attack scenario described by Fenske today and the report he presented in February 2019.

“The security of customer accounts is a top priority for the company,” a PayPal spokesperson said. “We are reviewing and evaluating all information and will take appropriate action to further protect our customers.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS