Cybercriminals are claiming to possess 15.8 million PayPal user credentials, including email addresses and passwords.

The alleged data dump appeared on a well-known hacker forum, sparking concerns about user security.
PayPal Denies Data Breach Claims
PayPal has firmly denied these data breach allegations. A company representative told investigators that no new security incident occurred, stating the claims relate to a 2022 credential stuffing attack that affected 35,000 accounts.
“There has been no data breach – this is related to an incident in 2022 and not new,” PayPal explained in an official statement.
The payment giant agreed to pay $2 million to US regulators in early 2025 to settle violations of New York’s cybersecurity regulations connected to that earlier incident.
While we can’t confirm this data breach happened, it would be a good PR move for PayPal to dismiss these reports.

What Data Was Allegedly Compromised
According to the threat actors, the stolen information includes:
- Login email addresses
- Passwords
- Associated PayPal URLs
- Account variants across different platforms
The cybercriminals claim the data was obtained in May 2025 and covers PayPal users worldwide. However, researchers couldn’t verify these claims due to insufficient sample data provided.
Hide Your Digital Fingerprint
Regardless, PayPal users should take immediate action to secure their accounts:
- Change PayPal passwords immediately
- Enable multi-factor authentication
- Use unique, strong passwords for each account
- Monitor financial statements regularly
TROYPOINT Tip: Never worry about identity theft again by using Aura which is TROYPOINT’s recommended identity theft protection.
Aura Identity Theft Protection Review
Infostealer Malware: The Likely Culprit
Security experts believe infostealer malware may be responsible for collecting this data rather than a direct PayPal system breach. These malicious programs silently harvest saved passwords, browser cookies, and login credentials from infected devices.
Infostealers like RedLine, Raccoon, and Vidar are readily available on dark web forums. They structure stolen data exactly like the alleged PayPal dump – with URLs followed by login credentials and passwords.
Final Thoughts
While PayPal maintains no recent breach occurred, this incident highlights ongoing cybersecurity threats. The relatively low asking price of $750 for the alleged dataset suggests questionable data quality.
Regardless of authenticity, users should remain vigilant about account security and consider comprehensive identity theft protection services.
For more details on this story, refer to the report from Hackread and potential updates from PayPal’s website.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.






All of my firesticks are getting outdated so what i wanted to know what would you suggest to replace them. Thanks Mike
Hi Mike see this – https://troypoint.com/best-android-tv-box/