PayPal confirms security breach at partner site

By

Online payment website PayPal confirmed that a breach of security had taken place at one of its partner sites last weekend and exposed a number of email addresses to hackers.

The break-in occurred at BenchmarkPortal where that company had not properly secured the online form it had used for customers to opt-out of a survey carried out by PayPal. A spokeswomen for PayPal said the number of emails gathered from this breach was "extremely limited".


"Information accessed did not include personal or financial information (like first/last names, credit card numbers, bank account numbers, social security numbers, driver's license numbers, etc.)," said Sara Bettencourt, spokeswoman for PayPal. "This information is kept under the highest levels of encryption on PayPal's secure servers. PayPal technology is and remains completely separate from BenchmarkPortal technology."

The form used showed the customer's email address to anyone who could correctly guess the survey form's ID. At the time of writing BenchmarkPortal was unavailable for comment.

Bettencourt said PayPal was "working directly with users who may have been affected to inform them of the situation". She urged users to be extra viliglent with emails claiming to be from PayPal.

PayPal
BenchmarkPortal

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

Log In

  |  Forgot your password?