/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Takeover of Brian Krebs' PayPal account illustrates why authentication via static identifiers (like SSN and DOB) is highly vulnerable to identity thieves

2016 Reality: Lazy Authentication Still the Norm  —  My PayPal account was hacked on Christmas Eve.

Krebs on Security Brian Krebs

Context & Ripple Effects

When Brian Krebs — the reporter who covers breaches for a living — lost his [[a:862673|PayPal account to an attacker armed with little more than his Social Security number and date of birth]], the lesson was not that PayPal was uniquely broken but that knowledge-based authentication was. The related coverage turns that one takeover into a seven-year arc of the same failure repeating at scale.

Months after Krebs' incident, the IRS built its breach-victim protection PIN on the same Knowledge-Based Authentication technology used in the original breach; by 2017 the FAFSA site was letting SSN-plus-birthdate combinations pull sensitive records; and by 2022-2023 both Experian and PayPal were caught out again — Experian exposing anyone's full credit report to name-address-DOB-SSN queries, PayPal confirming a credential-stuffing attack reaching ~35K users' addresses and SSNs.

First-order effects

  • PayPal customers whose recovery flows hinge on static identifiers are exposed right now: any thief holding leaked SSN and DOB data can answer the 'secret questions' and seize accounts, as Krebs demonstrated on his own account.

Second-order effects

  • Credit bureaus become the force multiplier rather than just another victim — the Experian flow that served up entire credit files from four public-ish identifiers means one weak gate feeds every downstream account-recovery attack.

Third-order effects

  • If the pattern holds, regulators face mounting pressure to retire the SSN as an authenticator entirely, pushing banks and bureaus toward dynamic, verifiable signals instead of knowledge-based questions that leaked data has already answered.

The trend: Knowledge-based authentication built on static identifiers is being steadily abandoned across finance and government as each new breach proves those answers are already in criminals' hands.