Someone has hacked my paypal

KlaudiaK

Banned - selling outside of the marketplace.
Joined
Jul 26, 2019
Messages
421
Reaction score
320
WTF! I have just seen someone has managed to hack my paypal and paid $50 for a digital ebook - how the fuck do i approach this, so annoyed by this.
 
First of all, get your password reseted. Then report this purchase
 
They'll probably get it back to you, it happened to me too.
 
Report to paypal instantly!! i prefer for you to call them . Also don't forget to put the 2 factor authentication instantly!!!! me personally whenever i log in i receive a code to my mobile phone and that mobile phone is a samsung phone with no camera neither can work with internet :D:D:D:D
 
Can you please elaborate how does it actually happened?

In reality it can happen only in 2 cases:

1. if your password is 12345 or similar

or

2. your computer infected with key-logger or some similar malware.

Would you be so kind and let us know.

Thanks a lot!
 
Do not rely on 2FA, it's not secure, YES IT DOESN'T! GSM carriers are the weakest point here and always will be. You need to understand how does it actually append.

First of all!!! assuming your PP is connected to your local Bank account.. visit your local bank branch and inform them so they would assist you and in case it is allowed in your country to direct debit your bank account (in most countries it is sadly) to put hold on it. then..

Do same things with all cards connected to it.. then,,

Get in touch with customer service, send them copy of your Gov issued ID and explain what's happened.

After that, In generally, you need to lean why this have happened.. I've mentioned most 2 common issues in my previous post and I can guarantee you no one would be able to "hack" your account if you do as follows:

1. use virus free OS (use legal windoz soft with good antivirus OR try Ubuntu, is not that scary as it sounds) [CLEAN OS RULE]
2. Keep your password strong and secure. [STRONG PASSWORDS RULE]
3. Check all the links you click and make sure it is not gaypal.com literally :) [AVOID PHISHING RULE]

Ppal is quite secure and it does not rely on cookies, sessions,IP, etc.. If you follow those 3 major rules above you should be safe for the foreseen future even without 2FA.

Good luck!
 
There's a load of ways your paypal can be hacked.
1. Phisher
2. Malware
3. Password guessed
4. Simswapped (doubt it unless you a real rich person not worth the time.)
Ton more but the first 2 are most likely.
 
There's a load of ways your paypal can be hacked.
1. Phisher
2. Malware
3. Password guessed
4. Simswapped (doubt it unless you a real rich person not worth the time.)
Ton more but the first 2 are most likely.

sorry but I have to respectfully disagree with "load of ways".. many of us know how all the ways how it can be done, can you mention just ONE "unknown" way? Please! I'm quite sure you can't.. no offense but most accounts get "hacked" caused by simple user negligence, it's sad but it's true..

P.S.
with freedom comes responsibility, unfortunately many of us willing to trade freedom for "their security"..
 
Do not rely on 2FA, it's not secure, YES IT DOESN'T! GSM carriers are the weakest point here and always will be.

1. use virus free OS (use legal windoz soft with good antivirus OR try Ubuntu, is not that scary as it sounds) [CLEAN OS RULE]
2. Keep your password strong and secure. [STRONG PASSWORDS RULE]
3. Check all the links you click and make sure it is not gaypal.com literally :) [AVOID PHISHING RULE]

Ppal is quite secure and it does not rely on cookies, sessions,IP, etc.. If you follow those 3 major rules above you should be safe for the foreseen future even without 2FA.
I'd argue with some of this. :p

There's no 100% safety, but 2FA is the safest option as of now. The chances to get your account hijacked while 2FA is enabled is very slim or at least it's slimmer than if you don't have 2FA enabled. Your average script kiddie won't have a clue how to circumvent 2FA or won't attempt it, he simply tries email password combos found on the internet or guesses the password or use a phishing site. In any of these cases, if he succeeds and you don't have 2FA enabled, you're fucked. Enabling 2FA, when it's an option, is always recommended especially for not too tech savvy people, who can't work out the difference between a legit and a phishing site or reuses passwords between sites. So 2FA is highly recommended for the vast majority of the internet population.
There are different types of the two factor or multi factor authentication, receiving a code via SMS is just one of those, for instance getting push notification on mobile devices is an option too in many cases.
While having a strong password is always a good idea, it doesn't need to be super strong, it's enough, if it's not guessable. If it's super strong, you only make your life harder, because you need to use a password manager, which is just another vulnerability. Passwords should be stored in your head, nowhere else. Figure out like 10 password variations (a mix of upper case, lower case letters, numbers, special characters), you feel, you can remember and that's it. The 10 variations should cover the important sites you visit (banking, shopping etc.), where it's a real issue, if someone else logs in. Most sites let 10 login attempts, before they lock you out. Worst case scenario, you need to ask for a password reminder.
Most account hijackings happen via keyloggers, phishing sites these days or via using email password combos from hacked/leaked databases. Brute forcing is not really common, using super strong passwords is an overkill.

You forgot an important piece of advice: don't reuse passwords between sites, because if one site gets compromised, all your accounts tied to the same email address become easily accessible, at least if you don't have 2FA enabled.

2FA provides another layer of security. It's always safer with it than without it.
 
I don't know about you guys but to me this sounds sketchy. Why would they only purchase an e-book that is $50? Why not something more expensive? This, to me sounds like you just bought an ebook and want your money back.
 
Enable SMS verification method.
I'd argue with some of this. :p

There's no 100% safety, but 2FA is the safest option as of now. The chances to get your account hijacked while 2FA is enabled is very slim or at least it's slimmer than if you don't have 2FA enabled. Your average script kiddie won't have a clue how to circumvent 2FA or won't attempt it, he simply tries email password combos found on the internet or guesses the password or use a phishing site. In any of these cases, if he succeeds and you don't have 2FA enabled, you're fucked. Enabling 2FA, when it's an option, is always recommended especially for not too tech savvy people, who can't work out the difference between a legit and a phishing site or reuses passwords between sites. So 2FA is highly recommended for the vast majority of the internet population.
There are different types of the two factor or multi factor authentication, receiving a code via SMS is just one of those, for instance getting push notification on mobile devices is an option too in many cases.
While having a strong password is always a good idea, it doesn't need to be super strong, it's enough, if it's not guessable. If it's super strong, you only make your life harder, because you need to use a password manager, which is just another vulnerability. Passwords should be stored in your head, nowhere else. Figure out like 10 password variations (a mix of upper case, lower case letters, numbers, special characters), you feel, you can remember and that's it. The 10 variations should cover the important sites you visit (banking, shopping etc.), where it's a real issue, if someone else logs in. Most sites let 10 login attempts, before they lock you out. Worst case scenario, you need to ask for a password reminder.
Most account hijackings happen via keyloggers, phishing sites these days or via using email password combos from hacked/leaked databases. Brute forcing is not really common, using super strong passwords is an overkill.

You forgot an important piece of advice: don't reuse passwords between sites, because if one site gets compromised, all your accounts tied to the same email address become easily accessible, at least if you don't have 2FA enabled.

2FA provides another layer of security. It's always safer with it than without it.

Absolutely agree in generally, if you deal with amounts less than 5-6 figures 2FA is good protection. I'd disagree with the notion that hackers are dumb and have no clue how to defeat 2FA, AFAIK it's quite common knowledge, just google it for the horrible stories of those poor soles who's blindly relied on 2FA and got hacked.. so I would not put too much trust on 2FA in generally when it comes to relatively large accounts or in that sense business accounts in generally to rely on 2FA as on "silver bullet ", it isn't!

I'm not saying one should not use 2FA, contrary, please use it by all means if you feel it helps, and it actually does as an addition measure.
what I'm saying is: try not rely on any "silver bullet" solution cause when it comes to personal (financial) security there's no such thing..

Sure, Never reuse passwords! instead adopt things like LastPass and KeePass, very useful! Keep encrypted file on the cloud AND copy on removable device.

Again, if your OS is secure, your password is strong, your business email similarly safe and you're phishing-proof then there's not much to worry about.
 
Last edited:
sorry but I have to respectfully disagree with "load of ways".. many of us know how all the ways how it can be done, can you mention just ONE "unknown" way? Please! I'm quite sure you can't.. no offense but most accounts get "hacked" caused by simple user negligence, it's sad but it's true..

P.S.
with freedom comes responsibility, unfortunately many of us willing to trade freedom for "their security"..
What do you mean, unknown to you and it's not your fault? Sim-swapping. If you run on RDP that can be cracked neither of these are your fault.
If a database was hacked into, your information could be leaked unaware to you and that too, is not your fault. Hey, even if your 9 year old son/brother sneaks into your laptop and downloads some hack for his game and they steal your money before you can check. That isn't really your fault either.

I win.
 
So someone hacked your PayPal and only spend $50?

What a stupid hacker.
 
Back
Top