{"id":244,"date":"2005-01-26T03:56:10","date_gmt":"2005-01-25T20:56:10","guid":{"rendered":""},"modified":"2005-01-26T03:56:10","modified_gmt":"2005-01-25T20:56:10","slug":"paypal-e-mail-leak-brings-phishing-worries","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2005\/01\/paypal-e-mail-leak-brings-phishing-worries\/","title":{"rendered":"PayPal E-Mail Leak Brings Phishing Worries"},"content":{"rendered":"<p>Electronic payment provider PayPal Inc. on Monday confirmed that a security breach at a partner site left an unknown number of e-mail addresses exposed on the Internet.<\/p>\n<p>The eBay-owned company, which has been a major target for phishing attacks, said the security breach occurred at Benchmark Portal, a third-party company that handles customer-survey e-mails and exposed a &#8220;limited number of user e-mail addresses.&#8221;<!--more--><\/p>\n<p>Word of the data leakage first surfaced on security message boards over the weekend and pointed to an apparent bug in the software used to manage &#8220;unsubscribe&#8221; requests from PayPal users.<\/p>\n<p>eWEEK.com was able to verify that certain readily available URLs could be manually manipulated to show e-mail addresses of PayPal users who recently unsubscribed from customer-service surveys.<\/p>\n<p>PayPal spokeswoman Sara Bettencourt said the breach had been fixed and insisted that only a small number of users were affected. However, security experts say a malicious person with the most basic scripting tool could have exploited the bug to hijack a large list of legitimate PayPal e-mail addresses.<\/p>\n<p>E-mail addresses are used to handle PayPal&#8217;s log-in process.<\/p>\n<p>&#8220;We&#8217;re working directly with those users whose e-mail addresses were exposed. We&#8217;re informing them of the situation and warning them they may receive deceptive e-mails. We&#8217;re encouraging them to contact us if they receive deceptive e-mails,&#8221; PayPal&#8217;s Bettencourt said.<\/p>\n<p>more from [url=http:\/\/www.eweek.com\/article2\/0,1759,1754013,00.asp]Eweek[\/url]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PayPal E-Mail Leak Brings Phishing Worries<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-244","post","type-post","status-publish","format-standard","hentry","category-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4bBYZ-3W","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=244"}],"version-history":[{"count":0,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/244\/revisions"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}