X
Contacted by us, but you never reached out to the ITRC? Ignore it - it’s a scam!
Skip to content
ITRC logo white final
ITRC-logo-color-final.svg

Support the ITRC

Business Login

Call Now 888.400.5530

  • Victim Help Center
  • Solutions

    Prevent Identity Theft

    Protect your identity from theft and misuse.

    Recover My Identity

    Get direct assistance, a custom remediation plan, and resources if you're a victim.

    Protect My Business

    Explore our business service offerings today.

    Breach Alert

    Get information on the latest data compromises.

    Additional Support

    Vulnerable populations can get additional support to help protect their identity.

  • Resources

    Insights

    Get the latest information on identity crimes.

    Newsletter

    Stay up-to-date on the latest news and happenings from the ITRC.

    Reports

    Explore independent surveys and studies from the ITRC.

    Podcasts

    Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    Events

    Explore upcoming events involving the ITRC.

    Newsroom

    Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact

PayPal Vulnerability with Login Patched After Being Discovered by White-Hat Hacker

Date: 01/15/2020

Home Help Center PayPal Vulnerability with Login Patched After Being Discovered by White-Hat Hacker

A PayPal vulnerability in the login system was recently discovered by a white-hat hacker, allowing the company to create a patch for the problem. When we picture highly skilled hackers at work, we might think of darkened rooms and faces peering out of black hoodies, lit by the glow of several computer monitors. At least, that is how Hollywood portrays these criminal masterminds who can break into a secure network from anywhere in the world and cause harm.

Fortunately, that is not often the reality. In fact, a number of hackers—the so-called “white-hat hackers”—like to sift around in a major company’s security defenses just to see what they can find. The company might pay them handsomely as a reward.

That was the case with a recently patched login vulnerability at PayPal. A hacker discovered that the Java script in the login page could potentially allow unauthorized outsiders to access accounts. Alex Birsan then reported the issue to PayPal and publicly disclosed it, for which he received over $15,000 from the company.

The method involved in accessing an account without authorization is so roundabout that PayPal has no reason to think anyone actually accomplished it. According to the company, an unsuspecting user would have had to go to PayPal by first clicking a button on a malicious website and entering their credentials to take advantage of the PayPal vulnerability. Then a hacker would have had to access the Google CAPTCHA that verifies the users’ identities on certain accounts. Still, there is no reason to leave a vulnerability unchecked, and PayPal created a patch for the PayPal vulnerability.

While PayPal users do not have to do anything to install this patch—since the issue was with PayPal’s own site, not downloaded user software—this is a good reminder that any time a vulnerability is discovered and a patch is issued, that patch will not be useful unless it is implemented. If the PayPal vulnerability had involved user software or apps, you would not be protected if you had not installed the latest update.

Contact the Identity Theft Resource Center for toll-free, no-cost assistance at 888.400.5530.

You might also like…

  • Epilepsy Foundation Cyberattack Leads to Weaponized Social Media Accounts
  • Business Ransomware Attack Leads to Hundreds of Employees Laid Off 
  • Landry’s Data Breach Shows Old Threats Don’t Die

How much information are you putting out there? It’s probably too much. To help you stop sharing Too Much Information, sign up for the In the Loop.

Get ID Theft News

Stay informed with alerts and newsletters from the Identity Theft Resource Center.

Global 100 2026 awards logo
ITRC 2026 Merit Award Winner
candid seal platinum 2026
Charity Navigator Badge Logo
Facebook-f X-twitter Youtube Linkedin-in Instagram
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Privacy Policy
  • Live Chat Policy
  • Accessibility
© Copyright 2026 – Identity Theft Resource Center

This website was supported in part by grant number 15POVC-21-GK-01092-NONF and 15POVC-22-GK-01803-NONF, awarded by the Office for Victims of Crime, Office of Justice Programs, U.S. Department of Justice. The opinions, findings, and conclusions or recommendations expressed in this product are those of the contributors and do not necessarily represent the official position or policies of the U.S. Department of Justice. View more about our copyright info here.

  • Victim Help Center
  • Solutions
    • Prevent Identity Theft

      Protect your identity from theft and misuse.

    • Recover My Identity

      Get direct assistance, a custom remediation plan, and resources if you’re a victim.

    • Protect My Business

      Explore our business service offerings today.

    • Breach Alert

      Get information on the latest data compromises.

    • Additional Support

      Vulnerable populations can get additional support to help protect their identity.

  • Resources
    • Insights

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Newsletter

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Reports

      Explore independent surveys and studies from the ITRC.

    • Podcasts

      Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    • Events

      Explore upcoming events involving the ITRC.

    • Newsroom

      Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact


  • Call Now 888.400.5530