Step one for PayPal would be to always provide a reason when they take action, for all users. Every bad experience I have had with PayPal began with them doing something negative, and never explaining why they did it. I have had methods of payment locked out, I have had funds not released, I have been told I could not make an instant payment, and not once was I given a reason why.
Try asking your regular bank how their fraud detection works, or your insurance company, or the secret service. Basically if you work in fraud detection (or broadly any kind of crime detection) you keep your techniques secret because otherwise you're helping the criminals avoid you. Look at the source code for Reddit or Hacker News, notice how in the publicly released codebases they've both chosen specifically not to…
Also don't want to help competing services.
Another data point - spammers used to check their work against spam assassin, fine tuning them.
Another data point - leaked password databases are a source of heuristics for generating word lists.