logoalt Hacker News

anonymous908213today at 3:30 PM2 repliesview on HN

Irrelevant to the current breach, but at the end of the article...

> In January 2023, PayPal notified customers of another data breach after a large-scale credential stuffing attack compromised 35,000 accounts between December 6 and December 8, 2022.

> Two years later, in January 2025, New York State announced a $2,000,000 settlement with PayPal over charges that it failed to comply with the state's cybersecurity regulations, leading to the 2022 data breach.

I didn't hear about this New York case. I'm the first to lament the incredibly sorry state of affairs of data security, to the extent that such security exists at all, but it is insane that you can get fined $2,000,000 for your customers re-using e-mail + password combinations between sites and becoming compromised as a result. I truly loathe mandatory 2FA with every fiber of my being and I guess New York would like to enforce it on the world? Sigh. Everything about the internet just gets worse and worse, continuously.


Replies

chrneutoday at 4:19 PM

I got like $230 from that paypal breach. Pretty rad.

thunderforktoday at 4:47 PM

You don't have to do 2FA, but there's liability in being vulnerable to credential-stuffing, and 2FA is one of many ways to mitigate that.