Over here in the European Union the regulations have mandated two factor authentication to be used for all online payments for the past few years. This means that when I pay with Paypal, Paypal texts me a code on my phone that I have to enter when making a payment, which effectively eliminates the possibility of fraud of the kind you were targeted with.
@calandale3 күн бұрын
They pay big money here to avoid having to provide such protections here.
@admscotty7046 күн бұрын
This sounds like a social engineering paypal scheme I have seen recently. They email you warning about a fake transaction for a large dollar amount, so you panic and login to the account which gives them your password credentials. Then they login with the stolen password and steal the money from your bank account. Do you have MFA enabled for paypal, even if they link your account to their ebay it still should request you to login?
@calandale5 күн бұрын
Nope. The transaction was present on paypal prior to anything I did. This had NOTHING to do with my ebay - which I basically don't use - the purchase was made with someone else's account, using my paypal info. Paypal allows for 'trusted sites' (and obviously ebay is for them) to bypass any MFA. It's a nice scheme.
@maubunky13 күн бұрын
Because of this video I ended up just buying a physical passkey for two factor authentication that I will henceforth link to my paypal account. So long as my physical key doesn't get stolen I guess I'll be better protected. I don't plan to keep it in my pocket as I have no use for paypal when I'm out driving around town.
@calandale3 күн бұрын
Make absolutely certain that 2FA is always invoked at moment of purchase. Previously, I had it set up on paypal, and they let me buy things without triggering it.
@kenx81765 күн бұрын
Thanks for the warning. I just unlinked mine.
@daviddelisle87056 күн бұрын
It is wise to keep a separate dispersal account, for example $1000 balance or what ever you are comfortable with to use in online purchases. Always have a buffer between your main accounts and online purchases. People have had accounts drained due to hacks on other companies records. You have NO control over the dimwitted practices at banks or other companies. Sorry this happened and I know it can feel like you were violated.
@kristoforogledhill75376 күн бұрын
Thanks for the warning Calandale
@admscotty7046 күн бұрын
One other thought, although a digital crime, have you opened a police report for investigation?
@calandale5 күн бұрын
I'm in the process of opening a fraud report through my bank. I don't see any point (beyond hassling myself further) for dealing with the cops.
@abramjones90916 күн бұрын
ACH transfers are pretty much a necessity for me, looks like I'm gonna have to keep a maximum of 1k in that account unless needed for immediate use
@calandale5 күн бұрын
I think there are protections OVER 1K. Of course, multiple purchases could be made.
@RolandoRatas7 күн бұрын
I'm at the end of the video and I don't know what exactly happened, you noticed a big Paypal transaction essentially an unauthorized debit from your Paypal but is it a purchase via your personal Ebay account or something more complex such as you sold something and someone is back charging for sold your items via your Ebay which they will keep and never return to you (doubtful it's the latter). You mention you purchasing something via a dodgy tobacco company that may have been hacked, if hacked they will have your login password for that tobacco, if your password for that tobacco company is the same or so similar to your Paypal password so that it can be guessed then it's likely that's the way they entered your Paypal account.
@calandale7 күн бұрын
No...someone else used their ebay account and was able to link my paypal to pay for it. The info to do this is stored both locally (on my computer) and on vendor sites. So, either paypal stores the information locally insecurely (as well as my computer being hacked) or some vendor was hacked.
@RolandoRatas7 күн бұрын
@@calandale oh ok thanks for the clarification. I'm an ebay seller (and occasionally a buyer) and I have security concerns with ebay and with paypal (I don't use them in conjunction). It probably means that in one of those vendors they had low security and someone copied their password database but cracked it by using their own password in the database as an example for the cracking software. Although strange that they should target your paypal details, whenever a website states 'save your credit card details for future use' I click on 'NO' !! Unless it's say Amazon or Ebay. In the UK right now for ebay sellers the law is this year that you have to provide them with your Social Security Number (N.I. Number in the UK) so if anyone were to hack into ebay they would have your ebay account, bank account, social security number and maybe even you bank credit or debit card for purchases - the full whammy ! Not great given that ebay has had data security breaches in the past. I really hope this thing gets sorted and you get your money back eventually.
@calandale7 күн бұрын
Bother, typed a long response better explaining things. Short is, the money is gone forever at this point - and the take-away is DO NOT link paypal (or any payments) through ACH - you have essentially no protections.
@RolandoRatas7 күн бұрын
@@calandale btw just going forward it's a good idea if you can in the U.S. to set up 'two step authentication' on your mobile phone for all payment accounts and banking, so whenever a new transaction is initiated manually you get a login code sent your cell / mobile phone. That would of / should have stopped the fraudsters. Or did they somehow get around that by switching it off your Paypal account ? It's a pain in the a$$ if it asks you every time when you log in to make a payment but it's secure, also some payment and banking online services only ask you for the code sent to your mobile when you log into them if they detect a change in the IP address of the device initiating manual payment.
@Enastra7 күн бұрын
Ah, sorry this happened to you. Hopefully you can get your money back and squared away soon.
@calandale7 күн бұрын
Nope - the money's gone. I tried to explain why in a response - but clicked off the box temporarily and lost a long post.