iTnews Asia
  • Home
  • News
  • Security

CSA issues alert on scam involving compromised PayPal accounts

CSA issues alert on scam involving compromised PayPal accounts

A total of 27 cases were reported since start of the year.

By Abbinaya Kuzhanthaivel on Feb 18, 2024 2:36PM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have issued an alert on a scam involving compromised PayPal accounts.

In these cases, victims would receive automated notifications from PayPal either in the form of emails or PayPal’s inbox messages, informing them of various activities such as profile changes and receipts for transactions on their accounts.

Upon checking their PayPal accounts, some victims discovered that funds from unknown sources were deposited, or that funds were being transferred to unfamiliar bank accounts added by the cybercriminals.

Subsequently, the cybercriminals would initiate a chargeback request. The victims would then receive an automated notification, and funds were recovered from their accounts, resulting in a deficit balance.

SPF said that a total of 27 such cases were reported from January 1 to February 9. 2024.

Law enforcement agencies have identified that compromising online credentials and passwords could be due to several reasons like using weak passwords, visiting phishing websites or downloading files infected with malware.

They had also warned about re-using the same password for multiple online accounts which may lead to data theft,

Currently, the public has been advised to adopt preventive measures such as implementing additional security features to PayPal accounts by enabling passkeys and two-step verification, using strong passwords consisting of at least 12 characters with uppercase and lowercase letters, numbers or symbols, and using different passwords for each of online accounts.

"Even if your PayPal account is inactive, you should still change your passwords from time to time as a best practice," CSA said.

It also recommends removing any devices that are no longer used or are not recognised in PayPal account’s “trusted device” list.

PayPal had recently in December 2023 revealed a credential stuffing attack on its servers that affected nearly 35,000 PayPal accounts, exposing personal information including names, addresses, social security numbers, tax identification numbers, and users' birth dates.

The company said unauthorised parties accessed PayPal customer accounts, but there is no evidence that login credentials were obtained through any company systems.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
© iTnews Asia
Tags:
cyber security agency security singapore police force

Related Articles

  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
  • Qantas hit by cyberattack, data of six million customers exposed
  • Your organisation’s physical security can be a gateway for cybercriminals
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Singapore sees no 'juice jacking' at transport charging stations, wi-fi points

Singapore sees no 'juice jacking' at transport charging stations, wi-fi points

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.