PayPal will pay a civil fine of $2 million for cybersecurity failures that led to a customer data breach in late 2022. Specifically, according to the New York State Department of Financial Services, the fine relates to the exposure of Social Security numbers about two years ago. customers'

Adrienne Harris, New York City's chief financial officer, said PayPal was not employing specialized staff to manage key cybersecurity functions and was not providing adequate training to address cyber risks.
See also: Indonesia: Google fined for Google Play payment system
As a result of these inadequate security measures, the names, dates of birth and social security numbers of PayPal customers, based in San Jose, California, were easily accessible for about seven weeks.
PayPal discovered the problem on December 6, 2022, after a security analyst uncovered an online message that read “PP EXPLOIT TO GET SSN.”
The next day, PayPal's cybersecurity team saw a spike in attempts to access its online platform. Cybercriminals were using "credential stuffing" techniques to view federal tax forms for tens of thousands of customers.
See also: Russia: Google fined for ignoring old penalties
Harris also said that PayPal did not require customers to use multi-factor authentication or controls like CAPTCHA to prevent unauthorized access.
According to the New York Financial Services Authority, the above violates the cybersecurity regulation adopted in 2017, which is why the fine was imposed on PayPal.
Fortunately, since the data was exposed, PayPal has upgraded its security.

The fine is not the only one imposed on a company for cybersecurity failures. Regulators around the world are increasing scrutiny of cybersecurity practices companies' and imposing tougher penalties for failures that put sensitive customer data at risk.
See also: Fine to the European Commission for violating GDPR!
The consequences of a data breach can extend far beyond monetary fines, as companies may also face reputational damage and loss of customer trust. As such, businesses should view cybersecurity not just as a compliance issue but as a critical aspect of their overall risk management strategy. They should take protective measures, such as conducting regular security audits, training employees, and establishing contingency plans in the event of an attack. By taking proactive steps to strengthen their cyber defenses, companies can better protect themselves from potential threats and demonstrate their commitment to protecting customer data.
Source: www.investing.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
