{"id":6224,"date":"2025-08-18T10:03:33","date_gmt":"2025-08-18T10:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/18\/threat-actor-allegedly-claiming-access-to-15-8-million-paypal-email-and-passwords-in-plaintext\/"},"modified":"2025-08-18T10:03:33","modified_gmt":"2025-08-18T10:03:33","slug":"threat-actor-allegedly-claiming-access-to-15-8-million-paypal-email-and-passwords-in-plaintext","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/18\/threat-actor-allegedly-claiming-access-to-15-8-million-paypal-email-and-passwords-in-plaintext\/","title":{"rendered":"Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext"},"content":{"rendered":"<p>    Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A threat actor operating under the alias \u201cChucky_BF\u201d has posted a concerning advertisement on a well-known cybercrime forum, claiming to possess and sell a \u201cGlobal PayPal Credential Dump 2025\u201d containing over 15.8 million email and plaintext password pairs.\u00a0<\/p>\n<p>The dataset, measuring approximately 1.16GB in plain text format, allegedly comprises sensitive credentials sourced from multi-domain PayPal accounts globally, highlighting the potential widespread impact of the breach.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. Cybercriminal \"Chucky_BF\" is alleged to be selling 15.8 million PayPal email and plaintext passwords.<br>2.\u00a0Breach enables credential stuffing attacks, targeted phishing campaigns.<br>3. PayPal users should immediately change passwords, enable multi-factor authentication (MFA).<\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-plaintext-passwords-exposed-nbsp\"><strong>Plaintext Passwords Exposed\u00a0<\/strong><\/h2>\n<p>According to Hackmanac\u2019s post on X, the leaked credentials reportedly contain:<\/p>\n<p><strong>Login Emails:<\/strong> Common domains such as @gmail.com, @yahoo.com, @hotmail.com as well as TLD-specific and country-centric addresses.<\/p>\n<p><strong>Plaintext Passwords:<\/strong> Both unique and frequently reused strings, many exhibiting strong complexity, raising concerns about password reuse across platforms.<\/p>\n<p><strong>Associated URLs:<\/strong> Direct PayPal endpoints, including URIs for \/signin, \/signup, \/connect, and Android mobile APIs.<\/p>\n<p><strong>Variants:<\/strong> Credentials embedded in regular PayPal links, country-specific domain formats, and mobile integrations.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfMajgxepU6Jygh063YWg7FVCv09AcONwmCurz-_uDImgVMugpOr0RDbce17KYUkzytai20lsFQkonB9ezujP5LnWXb6SNu45CYdDT_ra1GyplQS5Q7jVzsMETtLZ2e8na1nhbL1Q?key=1ou01hc6LjRyiPVLj_yfAw\" alt=\"Threat actor Advertises PayPal Data Leak\"><figcaption class=\"wp-element-caption\">Threat actor Advertises PayPal Data Leak<\/figcaption><\/figure>\n<\/div>\n<p>The forum post further displays a sample \u201ccode\u201d snippet showing the raw format\u2014email:password:url\u2014enabling <a href=\"https:\/\/cybersecuritynews.com\/north-face-fashion-brand\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential stuffing<\/a> attacks, targeted phishing, and large-scale fraud.\u00a0<\/p>\n<p>The threat actor notes a leak date of May 6, 2025, and describes the dump as suitable for use in phishing campaigns and security testing by malicious parties.<\/p>\n<p>TroyHunt added that \u201cGiven passwords definitely didn\u2019t come from PayPal in plain text, they\u2019ve either been obtained another way (info stealer, credential stuffing) or there\u2019s another explanation for this claim.\u201d<\/p>\n<p><strong>Security Measures for PayPal Users<\/strong><\/p>\n<p>While cybersecurity experts have not independently verified the full <a href=\"https:\/\/cybersecuritynews.com\/clickfix-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">authenticity<\/a> or scope of the dump, industry sources and threat intelligence feeds are actively monitoring related indicators.\u00a0<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Given passwords definitely didn\u2019t come from PayPal in plain text, they\u2019ve either been obtained another way (info stealer, credential stuffing) or there\u2019s another explanation for this claim <img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f914.png?ssl=1\" alt=\"\ud83e\udd14\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> <a href=\"https:\/\/t.co\/xmDyRaFbhL\">https:\/\/t.co\/xmDyRaFbhL<\/a><\/p>\n<p>\u2014 Troy Hunt (@troyhunt) <a href=\"https:\/\/twitter.com\/troyhunt\/status\/1956826362628751781?ref_src=twsrc%5Etfw\">August 16, 2025<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/figure>\n<p>If confirmed, such a breach would pose severe risks where attackers can automate login attempts across PayPal and other web services, exploiting reused credentials.<\/p>\n<p>The leak can enable highly targeted <a href=\"https:\/\/cybersecuritynews.com\/tag\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a>, using valid emails and password hints. Easy access to valid credentials could facilitate unauthorized transactions, banking fraud, and <a href=\"https:\/\/cybersecuritynews.com\/tag\/identity-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">identity theft<\/a>.<\/p>\n<p>Immediate action for all PayPal account holders includes resetting passwords on PayPal (and associated accounts), especially if reused elsewhere.<\/p>\n<p>Enable multi-factor authentication (MFA), monitor account activity for suspicious transactions, and remain vigilant for phishing attempts using breached email addresses.<\/p>\n<p>Security analysts underscore that this incident exemplifies the urgent need for robust password hygiene and use of MFA across financial and online services.\u00a0<\/p>\n<p>Organizations are advised to rapidly update breach detection rules for associated email and URL patterns, and end-users should never reuse passwords across critical accounts.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/paypal-email-and-passwords-leak\/\">Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/paypal-email-and-passwords-leak\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext A threat actor operating under the alias \u201cChucky_BF\u201d has posted a concerning advertisement on a well-known cybercrime forum, claiming to possess and sell a \u201cGlobal PayPal Credential Dump 2025\u201d containing over 15.8 million email and plaintext password pairs.\u00a0 The dataset, measuring [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-6224","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6224"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6224"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6224\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}