So as many of you know, someone hacked my PayPal account for $6,000. Here is what I have been able to piece together.
1) Sometime on Sunday, someone used a blackberry device (which i do not have) to access my PayPal account with my username and password and send $6k to another PayPal account. The belief by PayPal is this person got the information from another site with less security and tried it out on PayPal. The only problem with that is the two other sites that I use this username and password are T. Rowe Price and Facebook who I imagine have pretty robust security.
2) Despite this transaction being 20x larger than any I had ever made and being done on a blackberry device (which I had never used to make a payment via PayPal), PayPal OK’d it and took the money from my bank account (which was linked to PayPal) and actually funded the other person’s PayPal account. To repeat, PayPal security is so lax that it actually put $6k in this person’s account despite this transaction obviously being fraudulent.
3) Eleven minutes after funding this fraudster’s account, PayPal’s crack security algorithms realized something might be wrong. Luckily the money had not been withdrawn and PayPal was able to take back ownership of the $6k. Had this person moved the money fast enough, PayPal would be out $6k because they still refund fraud like this to users like myself.
4) Despite PayPal now identifying possible fraudulent activity, they never send me a text or email or call to notify me. Instead I notice this when I log into my bank on Tuesday and notice a $6k withdrawal from PayPal. How’s that for customer service?!?!
4) Now that PayPal has identified this as clear fraud, they claim that my money will be returned to my PayPal account on Friday, which I will then deposit into my bank account. Let’s keep our fingers crossed on this one.
The moral of this story for all of you is PayPal is no where near as secure as any of you believe or PayPal claims. The fact that this company would actually execute this transaction and ask questions later is astonishing to me and should scare the shit out of any PayPal user or eBay shareholder. For now, I will still use PayPal; however, Amex will be the only form of funding because I trust that company’s security 1000%.