The thief allegedly got the last 4 digits of the CC by posing as an employee.[0]
If true, it would mean paypal gave out financial information to an unknown third-party, which would be a breach of a bunch of laws, terms, internal policies etc.
The burden to prove innocence in this situation would definitely fall on paypal.
Excerpts from the original article[0]:
>I called paypal and used some very simple engineering tactics to obtain the last four of your card (avoid this by calling paypal and asking the agent to add a note to your account to not release any details via phone)
>Yes paypal told me them over the phone (I was acting as an employee) and godaddy let me “guess” for the first two digits of the card