This is what it says on the PayPal site, might be worth quoting all this back to them!
" Extensive protection against fraudulent transactions from your account
With PayPal, you have extensive protection against fraudulent transactions from your account.
To help you keep track of your account activity, PayPal sends an email confirmation of every account transaction.
In the unlikely event of receiving confirmation of a transaction you don?t recognise, our dedicated customer support team is there to help you. With PayPal, you typically won't be held liable for payments that you did not approve.
Data Security and Encryption
The security of your information, transactions, and money is the core of our business and our top priority at PayPal.
PayPal automatically encrypts your confidential information in transit from your computer to ours using the Secure Sockets Layer protocol (SSL) with an encryption key length of 128-bits (the highest level commercially available). Before you even register or log in to our site, our server checks that you're using an approved browser - one that uses SSL 3.0 or higher.
Once your information reaches us, it resides on a server that is heavily guarded both physically and electronically. Our servers sit behind an electronic firewall and are not directly connected to the Internet, so your private information is available only to authorised computers.
Which is why I think it might be an inside job. Get on the phone to them now! Don't worry, you'll get your money back.