15.8 Million PayPal Credentials Exposed in Major Data Leak on Dark Web

Silhouettes of business professionals seated around a conference table in an office setting with a large window overlooking a city skyline at sunset or sunrise, suggesting a meeting or corporate discussion taking place.

A significant data security incident has emerged involving PayPal, with reports indicating that 15.8 million PayPal credentials are being offered for sale on underground cybercrime forums. The dataset, posted by a threat actor operating under the name Chucky_BF, reportedly contains email and password combinations along with PayPal-related URLs. The incident follows a broader trend of credential exposure, coming just months after a massive leak of 16 billion login credentials from major technology platforms.

According to available information, the data collection occurred in May 2025. The leaked records include email addresses, plaintext passwords, and various PayPal-specific URLs, including endpoints for signin, signup, connect functions, and Android-specific URIs. The breach comes at a particularly sensitive time as PayPal has been working to strengthen its authentication systems with a new single-step login system to replace traditional two-factor authentication.

The dataset’s structure, which includes these specific PayPal endpoints, could facilitate automated credential stuffing attacks. The data is described as “raw email:password:url entries across global domains,” with credentials appearing to originate from infostealer malware logs that capture information from compromised devices. Recent research has shown that such infostealer malware variants have become increasingly sophisticated, with over 2,400 variants specifically targeting multi-factor authentication systems.

Technical analysis of the dataset indicates that while many of the exposed passwords demonstrate strong security characteristics, password reuse remains prevalent among the affected accounts. While many PayPal users employ multi-factor authentication (MFA), which provides an additional security layer, compromised login credentials still represent a vulnerability in the initial authentication barrier. The incident highlights the importance of PayPal’s ongoing transition to passkey authentication, which major tech companies are adopting as a more secure alternative to traditional passwords.

The scope of the incident encompasses 15.8 million individual records, making it a substantial data exposure event. The scale is particularly concerning given that credential stuffing attacks have seen a significant increase during recent years, with cybercriminals increasingly targeting financial services platforms. PayPal has been contacted regarding these claims but has not yet issued public confirmation or denial of the reported breach.

Sources: CyberNews, HackRead, AR15 Forums, SocRadar