This has nothing to do with HR.
When you click on buy, it takes you to PayPal website, which PayPal handles the login with HTTPS connection. HR website cannot read your password.
When you login to your PP account, all it does it transfer money to specified account (same as if you were to login manually from paypal.com, and click send money -> good and service, etc..)
You probably re-used your password somewhere and got combo'd, or downloaded some malware/keylogger somewhere which captured your password.