Brian Krebs, a renowned security researcher, wrote in a blog post blaming PayPal's lax user authentication procedures, which allowed an unknown attacker to compromise his account and then transfer funds to an ISIS-linked hacker believed to have been killed by the US military.
Mr. Krebs, who wrote for many years for the Washington Post, specializing in cybercrime-related syndicates and recently started a popular security-related blog, had previous dealings with PayPal during his long career.

Much to his surprise, after all these years, a recent incident showed how far behind the times PayPal's customer support program really is and how easy it is for someone to hack into other accounts with very little information.
We won't go into detail about what happened to Mr. Krebs, but in short, a hacker took control of his PayPal account by calling PayPal's customer service center.
So, the attacker requested a password reset and got it, only by providing the last four digits of Mr. Krebs' Social Security number and the last four digits of an older credit card account.
Since Mr. Krebs had exposed many cybercrime groups in the past, his personal details had been sought many times and his details are already available online in various places. For other people, details like these can easily be obtained from data breaches leaked online or from some criminal underground black market, where hackers sell large batches of data for a few dollars.
To Mr. Krebs' surprise, the account breach occurred twice, even after he informed PayPal of the first attempt and they assured him that they would monitor his account activity.
A call to a PayPal supervisor revealed that the company, in 2016, still lacks modern authentication systems that could avoid simple social engineering tricks like the one above, and in most cases, just a few static personal details are enough to reset passwords and change emails associated with accounts.
The breach of Mr. Krebs' PayPal profiles was apparently a targeted attack, because once the hacker took control of his account for the second time, he wanted to jeopardize Mr. Krebs' reputation by transferring some of his funds to the PayPal of a known ISIS terrorist.
The terrorist was Junaid Hussain, a hacker known as TriCk, a former member of TeaMp0isoN, as well as the leader of CyberCaliphate, one of ISIS's cyber wings.
To avoid future problems, Mr. Krebs recommends that PayPal should review its backup procedures for identifying its users and take into account the digitized world we live in and the countless data breaches that have exposed the personal information of almost every person who goes online on a regular basis.
