shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: PayPal

    Jan 31, 2025 9:19:27 AM

    The Target: Digital payments giant PayPal

    The Take: Hackers had access to names, addresses, Social Security numbers, individual tax identification numbers and dates of birth.

    The Vector: The threat actors behind the PayPal breach used a tactic called credential stuffing, where attackers use stolen username/password combinations from one data breach to attempt to log into other websites and services.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Topics:Know Your Breach

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates