- 01What a PayPal Account Takeover Looks Like
- 02What Hackers Actually Do Once They're In
- 03Why PayPal Accounts Get Targeted So Often
- 04Why This Moves Faster Than You'd Expect
- 05The First Hour: Step-by-Step
- 06Getting an Actual Human at PayPal
- 07Getting Your Money Back — What Actually Works
- 08If Money Was Sent From Your Balance, Not a Card
- 09What to Set Up Before This Happens to You
- 10Frequently Asked Questions
- 11The Bottom Line
It often starts with an email in the middle of the night: “You sent $840 to an account in another country” — for a payment you never made. By the time you open PayPal, your login may already be failing because someone else is in the account, racing to move money before you can stop it. This guide covers what to do in the first hour, how PayPal’s dispute process works, and what actually gets money back.
If your PayPal account is hacked, change your password immediately from a device you trust, then go straight to the Resolution Center and report the transaction as unauthorized — you have 180 days to file, but every hour matters because the attacker may still have access. If they’ve already changed your email or added a new bank account, use PayPal’s “account takeover” report path instead of the normal dispute flow, and call your card issuer directly if a linked card was used — a chargeback through your bank is a second, independent line of defense PayPal itself can’t undo.
What a PayPal Account Takeover Looks Like
The first warning usually looks routine — a payment confirmation, the kind PayPal sends automatically — until you read the amount and recipient. When you log in, the account may look different: a new bank account or card listed, an email address you don’t recognise, or a login history showing an unfamiliar device active minutes earlier. Those are the signs someone got in, and attackers tend to move fast.
What Hackers Actually Do Once They’re In
A PayPal takeover isn’t subtle once you know the pattern. The attacker isn’t browsing your transaction history for fun — they’re working through a short list of actions designed to extract money before you notice:
- Change the password and, where possible, the email on file to slow down your ability to log back in
- Add a new bank account or card they control as a withdrawal destination
- Send money to themselves disguised as a payment for “goods or services” — this can affect your buyer protections later
- Use your saved balance or linked card to buy gift cards or digital goods, which are hard to reverse once redeemed
- Send phishing “invoices” from your account to your contacts, since an invoice from a real account looks far more convincing than a random email
Why PayPal Accounts Get Targeted So Often
PayPal is a favorite target for the same reason it’s useful to you: it’s a direct bridge to real money, and it’s often protected by a password that was set up years ago and never changed. Most PayPal takeovers don’t start with anything sophisticated — they start with a password that leaked from an unrelated breach on a completely different site, and an attacker running that same email-and-password combination against PayPal, banks, and email providers in bulk. If you’ve ever reused a password across more than one account, that’s the most likely explanation for how someone got in, not a targeted attack aimed specifically at you.
Why This Moves Faster Than You’d Expect
PayPal’s own fraud systems are actually reasonably good at flagging unusual activity — but they’re built to catch patterns across millions of accounts, not to stop a single transaction in the ninety seconds after your password gets stolen. If the attacker logs in with your correct password (from a leaked or reused credential) rather than tripping an obvious red flag, the first transaction or two can clear before anything gets held for review.
If you get a text or email about “suspicious activity” with a phone number to call, don’t use it — verify by typing paypal.com directly into your browser and using Contact Us from there. Fake fraud-alert messages with a scam number attached are extremely common, and they specifically target people who are already anxious about a real account issue.
The First Hour: Step-by-Step
- From a device you trust, go to paypal.com directly (never a link from a text or email) and try to change your password immediately.
- If you can still log in, go to Settings → Security and remove any bank account, card, or email address you don’t recognize before doing anything else.
- Go to the Resolution Center and open a dispute on the unauthorized transaction — select “I didn’t authorize this transaction,” not the general “item not as described” option, since it routes to a different review process.
- If you’re locked out entirely, use PayPal’s account-recovery flow and specifically describe it as an account takeover, not a forgotten password — this routes you to identity verification instead of a simple reset email that the attacker would receive.
- Separately, call the bank or card issuer behind any linked payment method and tell them the card may have been used fraudulently through a compromised PayPal account. Ask about a temporary hold or replacement card.
- Screenshot everything: the transaction, the new (unfamiliar) bank account or device listed, and the exact time you noticed. PayPal’s review process asks for this level of detail.
Getting an Actual Human at PayPal
The Resolution Center is where the paper trail lives, but for an active account takeover, look for PayPal’s phone support option inside the app or on the Contact Us page after logging in — it’s tailored to your account and region rather than a single number that changes. If you’re getting nowhere through normal channels, @AskPayPal on X has historically been responsive to account-security issues and can sometimes escalate a case faster than the standard queue.
Getting Your Money Back — What Actually Works
You have 180 calendar days from the transaction to open a dispute in the Resolution Center, so don’t panic if you’re reading this a few days after the fact — but don’t wait either, since PayPal’s investigation looks at account activity patterns that are freshest right after the incident. If PayPal denies the dispute or takes too long, a chargeback through your bank or card issuer is a real, separate option — banks have their own fraud-liability rules under card network policies, and a chargeback doesn’t require PayPal’s cooperation to go through. Keep every screenshot and case number from PayPal’s side; your bank will ask for them.
If Money Was Sent From Your Balance, Not a Card
This is the harder case. Balance-funded transfers and “friends and family” payments have weaker recovery protections than purchases, because PayPal treats them more like cash — there’s no card network chargeback sitting behind them as a backstop. Report it as unauthorized in the Resolution Center regardless; PayPal can still reverse fraudulent transfers when there’s clear evidence of account takeover, but the odds and timeline are less predictable than a card-funded dispute.
What to Set Up Before This Happens to You
- Turn on two-factor authentication in PayPal Settings → Security — this alone stops most credential-based takeovers
- Use a password manager and a unique password for PayPal, never reused from another site
- Turn on email or push notifications for every transaction, so you see a fraudulent payment within minutes, not hours
- Periodically check Settings → Security for bank accounts, cards, or connected apps you don’t recognize
- Fund purchases through a linked card rather than your PayPal balance when possible, since card-funded transactions carry chargeback protection that balance transfers don’t
Frequently Asked Questions
How long does PayPal take to investigate an unauthorized transaction?
It varies, but expect anywhere from a few days to a few weeks depending on the complexity of the case and how much evidence you provide upfront. Cases with clear account-takeover signs — a new device, changed contact details, a location that doesn’t match your history — tend to move faster than ambiguous disputes.
Will I get my money back if I already lost the dispute once?
Not automatically, but you can usually escalate. If PayPal denies a dispute and you still have clear evidence of account takeover, a chargeback through your bank or card issuer is a genuinely separate process with its own review — a PayPal denial doesn’t bind your bank’s decision.
Is it safe to keep using PayPal after this?
Yes, once you’ve secured the account with a new password, two-factor authentication, and removed any unfamiliar bank accounts or devices. The underlying platform isn’t the weak point in most of these cases — a reused or leaked password almost always is.
The Bottom Line
Unauthorised PayPal transactions can often be recovered, and the Resolution Center dispute — backed by screenshots and a clear timeline you capture in the first hour — is usually what makes a case straightforward to review. If this is happening to you right now: secure the account first, dispute the transaction immediately after, and call your bank in parallel rather than waiting to see if PayPal resolves it alone. And once it’s over, take the one step that actually prevents a repeat: a unique password, stored in a password manager, that you’ve never used anywhere else. For other accounts, see our guides to Google and Instagram takeovers.
