The New York State Department of Financial Services (NYDFS) has imposed a $2 million fine on PayPal, Inc. for violations of its stringent cybersecurity regulations.
The penalty stems from failures in PayPal’s cybersecurity practices that led to a data breach in December 2022, exposing sensitive customer information, including Social Security numbers (SSNs), names, and dates of birth.
The breach occurred after PayPal implemented changes to its data flows to make IRS Form 1099-Ks accessible to a broader customer base.
However, the engineering team responsible for the rollout misclassified the project as a platform migration rather than a new feature.
This oversight bypassed critical risk assessments and vulnerability scans required under PayPal’s own policies. Consequently, the updated forms went live with unmasked customer data.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
Hackers exploited these vulnerabilities through a credential stuffing attack—a method where stolen username-password combinations from other breaches are used to gain unauthorized access.
Between December 6 and December 8, 2022, approximately 35,000 accounts were compromised. Attackers accessed sensitive nonpublic information (NPI), including SSNs and tax identification numbers.
Although no unauthorized transactions were reported, the breach exposed customers to identity theft risks.
NYDFS’s investigation revealed multiple lapses in PayPal’s compliance with its cybersecurity framework, which includes:
Superintendent Adrienne A. Harris emphasized the importance of robust cybersecurity measures in safeguarding consumer data.
“New York’s nation-leading cybersecurity regulation sets a critical standard for protecting sensitive information and ensuring the resilience of financial institutions,” she stated.
Harris criticized PayPal for failing to implement basic protections like MFA and CAPTCHA, which could have mitigated the breach.
The NYDFS Cybersecurity Regulation has been in effect since March 2017 and was recently amended in November 2023 to impose stricter requirements on financial institutions.
These include mandatory reporting of cybersecurity incidents within 72 hours and enhanced access control mechanisms.
Following the breach, PayPal took immediate action to mitigate the damage:
A PayPal spokesperson stated that “Protecting customer data remains a top priority and we take our regulatory responsibilities seriously”.
This event highlights the increased regulatory scrutiny that NYDFS-regulated fintech companies are subject to. Financial institutions should take note of the $2 million penalties as a warning about the consequences of poor cybersecurity procedures.
As cyber threats evolve, financial institutions must prioritize compliance with robust security frameworks to protect sensitive customer data and maintain public trust.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…