How to Secure a PayPal Account After Being Hacked: Steps to Regain Control and Prevent Future Attacks

Written by: Abigail Ivy
Published on:

If your PayPal account has been compromised, speed matters.

This guide explains how to secure a PayPal account after being hacked, what to check first, and which settings reduce the risk of another breach.

What to do immediately after a PayPal hack

The first priority is to stop further access and limit financial damage.

Even if you are not sure the attacker is still inside the account, treat it as an active incident.

  • Change your PayPal password right away using a device you trust.
  • Enable two-factor authentication, also called 2-step verification, if it is not already active.
  • Review recent activity, open disputes, and confirm whether payments, transfers, or refunds were sent without your approval.
  • Check the email address and phone number linked to the account for changes.
  • Sign out of all devices and remove unknown sessions if PayPal shows that option.

If you cannot log in because the attacker changed your credentials, use PayPal’s account recovery process immediately.

The faster you act, the more likely you are to stop unauthorized withdrawals, card linking, or changes to security settings.

How to secure a PayPal account after being hacked

To secure a PayPal account after being hacked, you need to combine account recovery, access control, and transaction review.

A password change alone is not enough if the attacker also has access to your inbox, phone number, or browser sessions.

1. Reset the password with a strong, unique value

Choose a password that has never been used anywhere else.

A password manager can generate and store a long, random password that is difficult to guess or reuse.

Avoid using names, birthdays, pet names, or variations of old passwords.

2. Protect the email account linked to PayPal

PayPal password resets and security alerts are often delivered by email, so your email inbox becomes a critical target.

Change the email password, enable multi-factor authentication, and look for forwarding rules or recovery addresses added by an attacker.

3. Verify your phone number and recovery options

Attackers sometimes change recovery details so they can intercept future login codes.

Make sure the phone number and backup email in your PayPal profile belong to you.

Remove any unfamiliar recovery methods right away.

4. Review linked financial instruments

Check every bank account, debit card, and credit card attached to PayPal.

Remove any payment method you do not recognize, and contact the card issuer if unauthorized charges have appeared.

If your bank account was linked, watch for small verification charges or test withdrawals.

Check for unauthorized transactions and account changes

Once access is restored, audit the account carefully.

Hackers may not only send money; they may also add a new shipping address, create recurring payments, or change notification preferences to hide their activity.

  • Review recent payments, refunds, and money transfers.
  • Look for new bank accounts, cards, or digital wallets added to the profile.
  • Check subscriptions and automatic payments.
  • Inspect addresses, contact details, and profile name for changes.
  • Search your email for PayPal messages about password resets, login attempts, or new device sign-ins.

If you find unauthorized transactions, report them through PayPal Resolution Center as soon as possible.

PayPal and your card issuer may have different dispute timelines, so act quickly and keep records of screenshots, dates, and transaction IDs.

Secure the devices and inboxes that were used to access PayPal

Many PayPal account takeovers start with malware, phishing, or a compromised email account.

If the attacker logged in from your computer or phone, clean those devices before using them for banking or payments again.

Scan for malware and suspicious apps

Run a full antivirus or anti-malware scan on every device that stored your PayPal credentials.

Update the operating system, browser, and security software.

On mobile devices, remove apps you do not recognize and revoke unnecessary permissions.

Update browser security

Clear saved passwords from browsers you do not fully trust, especially on shared or public devices.

Review browser extensions and remove anything unfamiliar, since malicious add-ons can capture logins or redirect traffic.

Harden your email account

A compromised inbox lets attackers reset passwords and monitor security notifications.

Change the email password, sign out of other sessions, enable app-based authentication where possible, and look for recovery settings that point to an unknown phone number or email address.

Contact PayPal support and your financial institutions

Reporting the incident helps document the fraud and may improve your chances of recovery.

Use PayPal’s official support channels rather than links in suspicious emails, since phishing messages often imitate support pages.

  • File a report in PayPal’s Resolution Center for unauthorized activity.
  • Ask whether any login alerts, device changes, or security actions are visible on the account.
  • Contact your bank or card issuer to dispute charges and block compromised payment methods.
  • Request replacement cards if card data may have been exposed.

If the attack involved a linked bank account, your bank may recommend closing the account or reissuing account numbers depending on the level of exposure.

Keep a written record of every support interaction, including dates, reference numbers, and the names of representatives.

How to prevent another PayPal compromise

After you secure the account, the next goal is to make a repeat attack much harder.

Strong account hygiene matters because PayPal is commonly targeted by phishing, credential stuffing, and social engineering.

Use unique passwords everywhere

Reused passwords are one of the most common reasons accounts get taken over.

A password manager makes it easier to keep PayPal, your email, and your banking accounts all on separate credentials.

Turn on 2-step verification

Two-factor authentication adds a second barrier even if your password is stolen.

App-based authentication is generally stronger than text-message codes because SMS can be intercepted through SIM swapping or number porting attacks.

Watch for phishing emails and fake login pages

Scammers often send urgent messages claiming there is a problem with your account.

Never sign in through a link in an unexpected message.

Instead, open a fresh browser tab and go directly to the official PayPal website or app.

Limit exposure on shared or public devices

Avoid saving PayPal credentials on public computers, and do not stay signed in on shared tablets, workstations, or family devices that other people can access.

Log out fully after each session.

Signs your PayPal account may still be at risk

Even after a password reset, ongoing warning signs can indicate the attacker is still nearby.

Pay attention to these red flags:

  • Login alerts you did not trigger.
  • Security settings change again after you restore them.
  • Emails about password resets or payments keep arriving.
  • Unknown subscriptions or recurring charges appear.
  • Your linked email account shows unfamiliar sign-ins or forwarding rules.

If any of these appear, repeat the recovery steps, secure your email first, and consider using a different device to manage the account.

Persistent suspicious activity may mean the underlying device or inbox is still compromised.

What information to keep for fraud reports

Detailed records make dispute resolution easier.

Save screenshots of unauthorized transactions, email alerts, altered account details, and any communication from PayPal or your bank.

Note the date and time you discovered the issue, when the attacker’s activity began, and which devices were in use.

This documentation can help support a fraud claim, especially if the case involves recurring payments, bank transfers, or identity theft concerns.

It also gives you a clear timeline if you need to explain the incident to PayPal, your card issuer, or law enforcement.