This story is horrifying because PayPal was the enabler. PayPal gave the attacker the last four digits of my credit card number over the phone That person should lose their job if it is not PayPal policy. I really hope by some small chance the person that did this gets some serious prison time, if not for this then anything else prior or down the road. Then maybe one of those mornings they wake up in prison they can…
It's possible that this was gross negligence on part of the employee and that the thief just got really, really lucky - but that seems unlikely. This is a systemic fault of PayPal and firing a lowly phone-jockey will not solve that. There are computer system protections that were clearly not in place (the representative was able to see this data on the screen, rather than having to enter it blind and have it validate…
Now they laxed the security somewhat and people give them sheet for that... There's no winning for them, is there?
But really, the employees should not give away any user information, ever. It should be a one way street here. That would have stopped the attacker in this case, as well, I believe...