I'm not a PayPal fan but reading how he supposedly obtained the digits, I immediately thought it was bullshit.
An insider seems likely, and it doesn't even have to be at PayPal. Most companies where you use your credit card either have your email, or could figure it out using your name / address.
But PayPal is probably just trying to cover their ass.