So my Paypal account was hacked at exactly 10:01am this morning. In the many years that I have been doing online transactions, I’ve gotten used to frauds and hacks but this one from Paypal (Unauthorized Transaction) is the biggest so far.
Just woken up before 10am this morning and was checking the blog when I received an email alert from Paypal (thanks to the GMail pop-up alert plugin). The heading says something like “Password Reset” so I immediately logged into my email and check what it was.
Realizing that someone tried to submit a “Forgot Password” request, I went to Paypal and logged in. After 2 failed attempts, I concluded someone got in and changed my password. But how? First came to mind was one of the email accounts attached to my Paypal account was hacked and used to reset the password.
Knowing that my GMail is still working (and is my primary Paypal account), I hurriedly went and did another password reset. Good thing I had my bank account details ready.
After being able to log back again, I found that funds were transferred to another account (that was fast! it only took him minutes). Unfortunately, it was a sizable amount.
The first thing I did was remove all the other email accounts linked to Paypal so the hacker can’t request another password change. I also changed my passwords and details.
I then filed for Dispute with Paypal. I thought this would be easy and will be resolved in my favor. Besides, I am the one claiming the transaction was un-authorized — the burden is on the recipient to prove otherwise. I had confidence it will be alright and done with.
Around 30 to 45 minutes later, I received an email from Paypal stating the transaction is valid. What? The recipient had a Non-US, Un-verified account. Paypal did not give any details why they decided against the claimant (me) and approved the transaction and closed the dispute.
There was no other way to re-open the case so I tried calling Paypal US but the Web PIN they gave me doesn’t work and I could not get thru.
Still thinking of ways to re-open that dispute. Will update once I get things cleared.
Update: Hacker got back again using password reset. They also changed my primary email so I am locked out now (it looks like they added a new email, onlinebuys@yahoo.com, and then made it primary email then deleted my email accounts). Already send an email to PayPal support, DMed @AskPaypal and tried calling the US number many times to no avail.
Update 2: I believe it was my fault that I did not immediately changed my GMail account. It was the one that was compromised although the password on the email was not changed the first time around that’s why I did not suspect the initial breach to come from there. I have since added the 2-step authentication method which also requires a PIN sent thru my mobile phone via SMS.
I also called my credit card company and asked if there were any charges passed on thru Paypal and glad that there have been none. I alerted them of the possibility though and they suggested I monitor it from time to time.
Update 3: After a few exchanges with @askpaypal over Twitter, a Paypal US rep called me last night over the phone and helped me restore my account. I have since gained back my original Paypal account. The 2 fund transfers made are also now under investigation.
Update 4: I just got an email stating that my claim for un-authorized transfer has been denied due to lack of evidence. I thought that after establishing that my account was hacked, it would have been evidence enough. I’m making an appeal.
Update 5: Both of the un-authorized transfers have now been reversed and everything is back to normal. Thanks to Paypal for the quick response and to all those who extended the help (local PR, agency, fellow tweeps and especially @askpaypal). That’s 32 hours from incident to resolution.
YugaTech.com is the largest and longest-running technology site in the Philippines. Originally established in October 2002, the site was transformed into a full-fledged technology platform in 2005.
How to transfer, withdraw money from PayPal to GCash
Prices of Starlink satellite in the Philippines
Install Google GBox to Huawei smartphones
Pag-IBIG MP2 online application
How to check PhilHealth contributions online
How to find your SIM card serial number
Globe, PLDT, Converge, Sky: Unli fiber internet plans compared
10 biggest games in the Google Play Store
LTO periodic medical exam for 10-year licenses
Netflix codes to unlock hidden TV shows, movies
Apple, Asus, Cherry Mobile, Huawei, LG, Nokia, Oppo, Samsung, Sony, Vivo, Xiaomi, Lenovo, Infinix Mobile, Pocophone, Honor, iPhone, OnePlus, Tecno, Realme, HTC, Gionee, Kata, IQ00, Redmi, Razer, CloudFone, Motorola, Panasonic, TCL, Wiko
Best Android smartphones between PHP 20,000 - 25,000
Smartphones under PHP 10,000 in the Philippines
Smartphones under PHP 12K Philippines
Best smartphones for kids under PHP 7,000
Smartphones under PHP 15,000 in the Philippines
Best Android smartphones between PHP 15,000 - 20,000
Smartphones under PHP 20,000 in the Philippines
Most affordable 5G phones in the Philippines under PHP 20K
5G smartphones in the Philippines under PHP 16K
Smartphone pricelist Philippines 2024
Smartphone pricelist Philippines 2023
Smartphone pricelist Philippines 2022
Smartphone pricelist Philippines 2021
Smartphone pricelist Philippines 2020
JC says:
oh shit.. that sucks bigtime.. i thought paypal was the safest..
Fleeb says:
@JC, it is not.
I read about PayPal. Most often than not they don’t care. Why? They are not regulated the same way as banks.
gonkyouka says:
Pretty scary..
echu says:
that’s scary…sounds like i have the same setup as you…so i’m interested how your email got accessed….any suspicion how that happened?
iva says:
couple of ellah pardilyo on facebook… have you checked?
benchmark says:
pede bang dalawa yung email address sa paypal? Di ba isa lang pede i-register dun? Nako….I think I have to deactivate my paypal account….teka…I have to na nga….it scares me…perhaps tama bro ko, hackable ang paypal. tsk tsk tsk
randz says:
that sucks.
jun says:
wow.. thats bad.. so maybe it is better if we withdraw our account on paypal.. after we had transaction..
deuts says:
I so thought too Paypal was safe. Had to reconsider using them.
harley mah-son says:
that is scary! i really thought that is is the safest!
i hope things will be okay! all my prayers to you sir yuga!