Almost 16 Million PayPal Credentials Leak Claim Sparks Security Concerns 

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer

A threat actor known as "Chucky_BF" is reportedly selling 15.8 million email and plaintext password pairs linked to PayPal accounts worldwide. While the authenticity of this claim remains unverified, immediate precautions are advised to secure user accounts.  

Details of the Claim  

The claim surfaced on underground hacking forums, where Chucky_BF offered the sale of 1.1 GB of data reportedly containing 15.8 million login emails and plaintext passwords. 

If true, the breach would represent a significant security threat to millions of PayPal users globally. 

PayPal data breach claim on a hacker forum
PayPal data breach claim on a hacker forum | Source: HackManac on X

However, cybersecurity professional Troy Hunt has expressed skepticism regarding the origins of the plaintext passwords. 

Possible Methods of Credential Theft  

Analysts speculate that the credentials, if authentic, may stem from incidents such as credential stuffing attacks or malware infections, rather than a breach of PayPal’s systems. 

Hunt noted, “Given passwords definitely didn’t come from PayPal in plain text, they’ve either been obtained another way (infostealer, credential stuffing) or there’s another explanation for this claim.”  

Credential stuffing involves attackers utilizing previously leaked passwords from other breaches, exploiting users who reuse passwords across multiple accounts. Similarly, info-stealer malware captures stored credentials from victims' devices, with hackers offering them in bulk on hacking forums.  

Regardless of the claim’s validity, users should adopt proactive measures to safeguard their accounts. Best practices include:  

Cybersecurity experts consistently emphasize the importance of adopting strong password management and authentication practices to mitigate the risks posed by potential breaches, such as the PayPal credentials leak.  

In June, the largest password breach compilation was revealed, comprising 16 billion credentials from various companies.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: