According to a PayPal notice of security incident dated January 18, attackers got unauthorized access to the accounts of thousands of users between December 6 and 8, 2022. The total number of accounts that were accessed by threat actors using a credential stuffing attack is reported as being 34,942. While accepting that PayPal is seemingly doing the best it can for the customers involved in this security incident by recommending password changes, Jasson Casey, chief technology officer at Beyond Identity insists that “passwords – whether unique or complex – are fundamentally flawed.” Instead, Casey says, organizations should be moving to phishing-resistant credentials such as the FIDO Alliance standard blueprints.


More

TechRadar: World Password Day 2025: All the news, updates and advice from our experts as it happened

Moving past passwords is improving brand trust The FIDO Alliance has also recently invited companies…

Read More →

ZD NET: Why the road from passwords to passkeys is long, bumpy, and worth it – probably

Out of the blue, I received a text from my father asking me, “What’s the difference…

Read More →

Forbes: Microsoft’s Password Deletion For 1 Billion Users—Do This Now

Your phone, computer and tablet is now at risk, as the nightmare of AI-powered attacks…

Read More →