Last night I received an email stating that my email address had been changed in my paypal account. I use this in conjunction with a small business I have and Paypal is linked to the business bank account where there is a fair bit of cash deposited..
Looking at the email it was hard to tell if it was just a spoof or a genuine email ( i didnt click on any links

I open a separate browser window and logged in to my Paypal account only to find that another email address had indeed been added and a new phone number had replaced mine.
I quickly changed them back, changed my two security questions and changed the password too..so no damaged done.
I spoke to the fraud team this morning and they said that whoever had hacked in used a london based VPN according to the IP addresses, but they could go no further. They did ask if I had an ebay account which i do, (not used in years). they didnt go in to detail but suggested that there is some security issue between the two platforms..so suggested that I change that too?
They advised putting two step authentication on the Paypal account and I must admit I didn't realise you could do that with Paypal (I have it on all my betfair accounts by the way).
The two step doesn't work quite the same as betfair, you receive a text rather than use the google authenticator.
So after a long winded email; If you dont have two step on your paypal account, its worth doing!
Regards
Peter