I am pretty shocked that Paypal would not notice and stop, such large movements of cash. My bank would have stopped it.
Firstly I have never used either PayPal or E-Bay on public WiFi my personal phone line was hacked to steal data. Attempts by both PayPal and E-Bay to contact me by phone, my e-mail was diverted, failed as they had placed a call diversion on my line to a false number. How they did that BT (our phone company) have yet to tell me and probably will not after speaking to a fairly high level person in the fraud and security dept. that facility has never been enabled on the line by BT. They physically checked the line for what is called a T ie a tap but it was clean at the time.
My E-bay was hacked as well and fake ads for £5,0000 Rolex watches placed.
It seems the fraud involved a "buyer" taking a buy it now then lodging a claim for non delivery. The payment going in by PayPal and straight out to their account set up by them, so no loss or gain for them then the claim for a non delivery refund being taken from my bank account to "repay" the false buyer.
To my eyes the Rolex auctions were obvious fakes but EBay did not take them down, many times I have reported clearly fraudulent Hasselblad H5D ads never thought my account would host a similar one!!
As I had not sold anything on Ebay for three years you may have thought their software would have flagged an issue when three Rolex £5,000 watches went on!!
You are perfectly correct that plain passwords are poor protection but my on line bank account was secure because they use a web page that only takes a random part of the password that changes each time and the order is different to log in and you can't opt to stay logged in or save the password. Paypal and Ebay both take full password each time and allow browsers to store them so much easier to hack.
They had ordered TVs as well and other goods on line using the Pay Pal account but all were blocked in time, you may think the delivery addresses would help tracking them but the volume of this kind of fraud is such that as in this case of no loss there are no resources to pursue them I was told.
Apologies for this long OT post but forewarned is forearmed.