Last night while having a nap before work the familiar vibration indicating a new email came from my phone. Despite needing to get some shut eye I decided to check it out to see what exciting products GrabOne had for sale today. Instead I found an email from PayPal indicating that I had just sent $98 USD to an email address I've never heard of (conveniently charged to my CC). Queue mild panic. After failing to login a few times due to password error (I hardly ever use the account and set the password deliberately hazy) a reset password was in order. Upon logging in, low and behold a payment of $98 USD (charged at $131.60 NZD) had been made half an hour earlier. Thankfully it had not been claimed by the email address (a non PayPal user) so it was easy to cancel (although PayPal are yet to return to money).
Now what's got me is how they gained access to the account. The account gets very little use (a few auto payments each month and the occasional one off purchase). The password was unique and not similar to any other password I use. I am fully aware of phishing and am a stickler for checking ssl and typing in websites myself. I have not signed up to any new service in months nor made any one payments in months. The one and only machine used to login is subject to daily scans from MSE and Maleware-Bytes as well as weekly manual checks with the likes of hijackthis. No other accounts have been compromised (although all passwords have now been changed from phone) including the wifey's PayPal which she uses a lot more than me.
Other than the unauthorised payment, nothing else was altered on the PayPal account itself. I had recently set new security questions and updated all my details. An obligatory email to PayPal is yet to be answered. Everything that can be scanned, poked, prodded and inspected has been (we only have the 1 pc) and I can't find any hint as to how my account details were accessed. What am I missing?
What is also bugging me is why didn't PayPal's much hyped (and much hated) Anti Fraud system detect something was a miss. In the 10 years I've used that account, I've never sent money to a non-registered email account nor have I sent that much (I've heard too many horror stories with PayPal to entrust them with anything more than small transactions). The accounts have never been accessed outside of NZ (although I'm only speculating that it was on this occasion). Is it possible that smaller transaction (say under $100 USD) are not subject to the same scrutiny as larger ones?
Any thoughts appreciated (although please no Scan everything and Change your passwords etc, this has been done).
Cheers,