Actually, neither the hacker nor PayPal has presented any proof whatsoever (there is as yet no proof that the hacker even had the last four digits of the card number, and if he did, there are plenty of sources to get those from).
Either could for all we know be telling the truth, but if you find yourself automatically taking the word of a known thief over that of a legitimate company, it's time to stop and re-examine, not only your conclusion in this case, but every aspect of the thought processes you use for such things. The hacker had several possible incentives to lie, and I'm sure you'd be able to figure out at least some of them if you stepped back and looked at the question objectively.
Either could for all we know be telling the truth, but if you find yourself automatically taking the word of a known thief over that of a legitimate company, it's time to stop and re-examine, not only your conclusion in this case, but every aspect of the thought processes you use for such things. The hacker had several possible incentives to lie, and I'm sure you'd be able to figure out at least some of them if you stepped back and looked at the question objectively.