A simple message on Twitter is enough to hack your PayPal account..
An anonymous user posted photos on Imgur, describing how a Paypal disabled two-factor authentication (2FA) - one of the company's most advanced user protection systems - from his account without first verifying his identity by asking him the necessary security questions.
Social engineering is the most common method of account hacking based on basic human interactions, where ordinary users try to convince or deceive other people, thus breaking common security practices.
If you work for one of the largest online payment processing companies and a random Twitter user convinces you to disable two-factor authentication by providing only an email address, then this is a classic case of social engineering that definitely needs further investigation. While everyone may hate the lengthy security questions asked by employees during online or phone customer service, none of us want to be left out.
Let's hope that this was just an isolated incident for PayPal and that the following dialogue, which took place via Twitter, will result in some kind of training manual for the company's customer service department.
Below is the surprising conversation between the Pay Pal employee and the account owner, along with the email confirming the deactivation of the two-factor authentication mechanism, as well as the response from the company's bug bounty department, which states that social engineering is not included in the reward program provided for reporting security vulnerabilities found in Paypal's services.
The two-factor authentication deactivation confirmation email:
The response from the company's bug bounty department:

![Unbelievable blunder by a PayPal employee [Photos] 1 PayPal](https://www.secnews.gr/wp-content/uploads/2015/07/Pay-Pal.png)
![Unbelievable PayPal employee blunder [Photos] 2 PP1](https://www.secnews.gr/wp-content/uploads/2015/09/PP14.jpg)
![Unbelievable blunder by a PayPal employee [Photos] 3 prep](https://cdnglobal.secnews.gr/wp-content/uploads/2015/09/20151803/ppreply1.jpg)
![Unbelievable blunder by a PayPal employee [Photos] 4 pp bug bounty](https://cdnglobal.secnews.gr/wp-content/uploads/2015/09/20151804/pp-bug-bounty.jpg)