PayPal sent you a verification code you didn't request
A PayPal code you didn't ask for means someone entered a working password and reached the second step of a login.
PayPal is worth treating differently from a shopping account, because it holds a balance, links directly to your bank, and carries standing permissions that keep working after you change your password.
What to do
1. Change your password from paypal.com directly
Type the address yourself. PayPal phishing is among the most heavily imitated in existence, and a message about a verification code is a natural place to hide a fake login page. Change the password in Settings, under Security.
2. Review automatic payments and billing agreements
This is the step specific to PayPal, and the one that matters most. Under Settings, Payments, you'll find automatic payments and billing agreements you've granted to merchants over the years. These continue to draw funds independently of your password.
Read the list. Cancel anything you don't recognize or no longer use. An attacker who briefly had access may have authorized a merchant that keeps charging long after you've locked them out.
3. Check permissions granted to third-party apps
Also under Security, look at the apps and services connected to your account. Revoke anything unfamiliar. Like billing agreements, these survive a password change.
4. Upgrade the second factor
If you're on SMS codes, move to an authenticator app or a security key in the Security settings. PayPal supports both, and text codes are the weakest option because they can be intercepted through a SIM swap.
5. Read recent activity and linked accounts
Check your transaction history for payments you didn't make, then check linked bank accounts and cards for anything added. Look at pending transfers as well as completed ones.
6. Secure the email address on the account
Password resets go there. Change that password too, and check the inbox for forwarding rules or filters you didn't create, which is how someone keeps reading your mail after you think you've locked them out.
Where the password came from
Not from PayPal. Attackers buy credentials leaked from breaches at unrelated companies and replay them in bulk against financial services, which pay better than anything else on the list.
What makes an attempt targeted rather than random is the information around the password. Your current phone number, email address, and home address let someone pass a verification question, or make a support call convincing enough that you hand over the code yourself.
Data brokers and people-search sites publish that combination openly. They compile it from public records and commercial sources, and sell it to anyone. A leaked password and a current phone number are a far more dangerous pair than either alone.
Delist finds those listings, files the removals, and re-checks them, since a profile taken down often returns within weeks. Run a free scan to see what's published about you.
The broader pattern is covered in why you're suddenly getting 2FA codes you didn't request.
Frequently asked questions
Does an unrequested PayPal code mean my account was accessed?
No. The code is sent after a password is accepted but before access is granted, so the second step held. The password is compromised, which is the thing to fix.
I changed my password. Am I done?
Not quite. Billing agreements, automatic payments, and third-party app permissions keep working after a password change. Review all three before you consider it closed.
Someone emailed saying my account is limited and I need to verify. Is that real?
Check by going to paypal.com yourself and looking for a notice in your account. Account-limitation emails are one of the most common phishing templates, and they arrive alongside real attacks precisely because the timing makes them believable.
Can someone drain my linked bank account?
That's the reason to move quickly. Review linked accounts, cancel unrecognized billing agreements, and contact both PayPal and your bank if you find a transfer you didn't authorize.
Should I use PayPal's security key option?
Yes, if you have one. A hardware key or an authenticator app is meaningfully stronger than SMS, and PayPal supports both in Security settings.
Find out what data brokers know about you
Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.
Start your free scan →