"They remote connected in at 5AM MT, went into my Chrome and used my PayPal to buy about $3k worth of gift cards. And yes, I had two-factor authentication."
"They remote connected in at 5AM MT, went into my Chrome and used my PayPal to buy about $3k worth of gift cards. And yes, I had two-factor authentication."
I mean, unless the hackers logged in, left the 2FA prompt up and then a user completed the 2FA exchange, but that would be a foolish thing to do anyway...
edit: thanks for the answers; makes sense!
Your paypal account getting hacked isn't a Big Deal, you aren't going to lose any money over it. In fact, managing that is paypals entire business model.
How is it easier to break Teamviewer's 2FA implementation than PayPals?
I (think I) now understand why "and my PayPal has 2FA enabled" points to TV being compromised -- If the PayPal account has 2FA active, and they were still "hacked", then it points to an existing session being hijacked. And a probable cause of that would be a compromised TV session.
So it's not necessarily an indication that TV's 2FA was compromised, but rather that TV was compromised in general, allowing the hacker to hijack TV sessions. (I'm imagining that the TV 2FA happens on their central server, and not on the actual server daemon running on the target remote machine... so if the central server was compromised...)
edit: Obviously this is entirely speculative, I don't know any of what's going down, but it resolves my initial curiosity.
Yet, we've heard from people who have used passwords unique to TeamViewer, who have enabled two-factor authentication, and have found no malware on their computers, losing control of their systems in the past few days via TeamViewer.
Apparently TV disagrees, but in this case I'm inclined to believe their unfortunate users.