Takeover of Brian Krebs' PayPal account illustrates why authentication via static identifiers (like SSN and DOB) is highly vulnerable to identity thieves
2016 Reality: Lazy Authentication Still the Norm — My PayPal account was hacked on Christmas Eve.
Context & Ripple Effects
When Brian Krebs — the reporter who covers breaches for a living — lost his [[a:862673|PayPal account to an attacker armed with little more than his Social Security number and date of birth]], the lesson was not that PayPal was uniquely broken but that knowledge-based authentication was. The related coverage turns that one takeover into a seven-year arc of the same failure repeating at scale.
Months after Krebs' incident, the IRS built its breach-victim protection PIN on the same Knowledge-Based Authentication technology used in the original breach; by 2017 the FAFSA site was letting SSN-plus-birthdate combinations pull sensitive records; and by 2022-2023 both Experian and PayPal were caught out again — Experian exposing anyone's full credit report to name-address-DOB-SSN queries, PayPal confirming a credential-stuffing attack reaching ~35K users' addresses and SSNs.
First-order effects
- PayPal customers whose recovery flows hinge on static identifiers are exposed right now: any thief holding leaked SSN and DOB data can answer the 'secret questions' and seize accounts, as Krebs demonstrated on his own account.
Second-order effects
- Credit bureaus become the force multiplier rather than just another victim — the Experian flow that served up entire credit files from four public-ish identifiers means one weak gate feeds every downstream account-recovery attack.
Third-order effects
- If the pattern holds, regulators face mounting pressure to retire the SSN as an authenticator entirely, pushing banks and bureaus toward dynamic, verifiable signals instead of knowledge-based questions that leaked data has already answered.
The trend: Knowledge-based authentication built on static identifiers is being steadily abandoned across finance and government as each new breach proves those answers are already in criminals' hands.