{"id":17132,"date":"2020-08-10T20:14:57","date_gmt":"2020-08-10T16:14:57","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/how-to-secure-paypal\/17132\/"},"modified":"2020-08-10T20:14:57","modified_gmt":"2020-08-10T16:14:57","slug":"how-to-secure-paypal","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/how-to-secure-paypal\/17132\/","title":{"rendered":"How to secure PayPal"},"content":{"rendered":"<p>With hundreds of millions of users around the world, PayPal has long been an international leader in the electronic payments industry. But as we know, money never fails to attract fraud, especially now, with as much of life as possible taking place online. Here is what you need to do to stay safe when sending or receiving money through PayPal.<\/p>\n<h2>How secure is PayPal?<\/h2>\n<p>As a matter of fact, PayPal is quite a reliable platform that maintains a high level of security \u2014 and keeps improving it. Thus, the company has an official program deploying white hat hackers to unearth vulnerabilities (the so-called bug bounty), under which it has already <a href=\"https:\/\/hackerone.com\/paypal?type=team\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">paid out almost $4 million<\/a> since 2018. The program also covers several other services owned by PayPal, such as Venmo.<\/p>\n<p>PayPal also treats its users\u2019 data responsibly: It did have one reliably reported leak, in 2017, but the leak involved the infrastructure of a company PayPal <a href=\"https:\/\/www.trendmicro.com\/vinfo\/es\/security\/news\/cybercrime-and-digital-threats\/paypal-reports-data-breach-affects-1-6-m-tio-customers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">was acquiring at the time<\/a>. And all payments within PayPal are based on e-mail addresses, so users never have to share their bank details with vendors.<\/p>\n<p>Technology aside, we cannot ignore the human factor. Even though PayPal does a lot to secure its users\u2019 transactions, users themselves sometimes make mistakes that cost them real money. To avoid their fate, follow these simple rules.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-cyberattacks\">\n<h2>Protecting your PayPal account<\/h2>\n<h3>Protection against hacking in PayPal<\/h3>\n<p>First, make sure your PayPal account has a reliable password. Reliable means long, unique, and hard to guess. If you use a weak password, or use the same password for lots of accounts, then your PayPal account will be vulnerable to <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/brute-force\/\" target=\"_blank\" rel=\"noopener noreferrer\">brute-force attacks<\/a> or <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/credential-stuffing\/\" target=\"_blank\" rel=\"noopener noreferrer\">credential stuffing<\/a>. Crafting a good password isn\u2019t hard \u2014 <a href=\"https:\/\/www.kaspersky.com\/blog\/strong-password-day\/25519\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">here\u2019s how<\/a> \u2014 although managing a bunch can get unwieldy. Regardless, you may find refuge in our <a href=\"https:\/\/me-en.kaspersky.com\/password-manager?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">password manager<\/a>. It will do both: generate reliable passwords and safely store them.<\/p>\n<p>With finances at stake, it pays to be on the safe side. Do not fail to activate two-factor authentication. With PayPal, you can receive one-time codes in text messages or generate them in an application \u2014 <a href=\"https:\/\/www.kaspersky.com\/blog\/2fa-practical-guide\/24219\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">whichever authentication app suits you best<\/a>. The app-based option is generally considered more reliable, but any second factor is better than none at all, so if you strongly dislike using an authentication app, at least use one-time codes delivered by SMS.<\/p>\n<p>Think twice about your secret questions and answers, too. Your grandmother\u2019s maiden name or your first school probably isn\u2019t hard to learn from your social network accounts; <a href=\"https:\/\/www.kaspersky.com\/blog\/security-questions-are-insecure\/13004\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">questions like that offer feeble protection<\/a>. You can be more clever than that. For example, instead of using the name of your old school, fill in the answer of one of your relatives or friends \u2014 just don\u2019t forget what the right answer should be. For safety reasons, we recommend using <a href=\"https:\/\/me-en.kaspersky.com\/password-manager?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a> for that as well; it also stores encrypted notes, not just passwords.<\/p>\n<p>In addition to ramping up authentication, make sure you have notifications set up so they work right for you. Enabling mobile push messages about outgoing payments will probably be the most useful measure in terms of security. That way, if someone breaks in to your account and begins spending your money, you\u2019ll be sure to learn about it, and put a stop to it, right away.<\/p>\n<p>A somewhat less-intuitive addendum: Even though you\u2019re receiving notifications, you should perform a manual check of your account and transaction history from time to time. If you find PayPal reporting transactions you clearly didn\u2019t make, change your password and security questions and contact PayPal\u2019s support immediately.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kpm-download\">\n<h3>Vulnerability protection in PayPal apps<\/h3>\n<p>Software is written by people, and people make errors, and errors become vulnerabilities that cybercriminals can exploit. As we mentioned above, PayPal spends big money to search out such vulnerabilities \u2014 and probably even bigger bucks to purge them from its products and systems.<\/p>\n<p>But for the resources that PayPal continuously invests in your protection to work, you will have to put in a small amount of effort. Namely, never skip smartphone app updates. (Desktop users have to use the Web version of PayPal, so if you use that, you have another reason never to skip browser and OS updates.) Install all updates as soon as they come out.<\/p>\n<p>Do not forget to run antivirus scans on the devices you use for PayPal \u2014 <a href=\"https:\/\/me-en.kaspersky.com\/plus?icid=me-en_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kplus___\" target=\"_blank\" rel=\"noopener\">your PC<\/a> and <a href=\"https:\/\/me-en.kaspersky.com\/mobile-security?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____3d7d2c33c4c17a10\" target=\"_blank\" rel=\"noopener\">your smartphone<\/a>. When your money is at risk, no precaution is too small.<\/p>\n<h3>Cyberattack protection in PayPal<\/h3>\n<p>Always remember that public Wi-Fi is bad (meaning unsafe). Never use it for financial transactions without ensuring you have a secure connection. If you are pressed to complete a transaction while using free Wi-Fi at a caf\u00e9 or airport, first establish <a href=\"https:\/\/me-en.kaspersky.com\/vpn-secure-connection?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____vpn___\" target=\"_blank\" rel=\"noopener\">a secure VPN connection<\/a> and only then open your PayPal app.<\/p>\n<p>Use caution with incoming e-mails that seem to come from PayPal; they may pose a phishing threat. PayPal has long occupied a place <a href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2019\/08\/25\/microsoft-paypal-facebook-warning-top-10-brands-impersonated-in-phishing-attacks-revealed\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">at the top of the list of brands most targeted by fake e-mail scams<\/a> \u2014 and why wouldn\u2019t it? Fraudsters follow money, remember? Use <a href=\"https:\/\/www.kaspersky.com\/blog\/phishing-ten-tips\/10550\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">standard observation techniques to detect phishing<\/a>: Carefully check the sender\u2019s address and any links in the message.<\/p>\n<p>Better yet, do not click any links at all. Instead, enter PayPal\u2019s address in your browser, log in, and check whether you have any notifications in your account. If you have none, the letter is very likely fake.<\/p>\n<p>And, most important, never enter your PayPal account credentials if you have even a shadow of a doubt about the legitimacy of the letter or website you find yourself dealing with.<\/p>\n<p>Some recommend using PayPal from a browser or even separate device used solely for that purpose. We think that\u2019s a bit much. Instead, use the Safe Money feature in <a href=\"https:\/\/me-en.kaspersky.com\/plus?icid=me-en_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kplus___\" target=\"_blank\" rel=\"noopener\">Kaspersky Plus<\/a> to ensure your money will never be stolen when making a payment.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-banking\">\n","protected":false},"excerpt":{"rendered":"<p>Your online finances need proper protection. Learn how to secure your PayPal account.<\/p>\n","protected":false},"author":2548,"featured_media":17133,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[2088,1047,806,104,76,179,1750,131,677],"class_list":{"0":"post-17132","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips","8":"tag-tips","9":"tag-2fa","10":"tag-online-finances","11":"tag-paypal","12":"tag-phishing","13":"tag-safe-money","14":"tag-secure-connection","15":"tag-tips-2","16":"tag-vpn"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/how-to-secure-paypal\/17132\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/how-to-secure-paypal\/21669\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/how-to-secure-paypal\/8490\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/how-to-secure-paypal\/22999\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/how-to-secure-paypal\/21189\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/how-to-secure-paypal\/19887\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/how-to-secure-paypal\/23620\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/how-to-secure-paypal\/22532\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/how-to-secure-paypal\/28871\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/how-to-secure-paypal\/36678\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/how-to-secure-paypal\/15433\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/how-to-secure-paypal\/15907\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/how-to-secure-paypal\/13853\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/how-to-secure-paypal\/24895\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/how-to-secure-paypal\/28987\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/how-to-secure-paypal\/25841\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/how-to-secure-paypal\/22709\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/how-to-secure-paypal\/27959\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/how-to-secure-paypal\/27789\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/tips-2\/","name":"tips"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/17132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2548"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=17132"}],"version-history":[{"count":0,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/17132\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/17133"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=17132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=17132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=17132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}