Hi,
1. Well, it would be explained by the email address being changed in the settings of your PayPal payment method.
For example, if a hacker gained access to your backend in some way and then enter his email address instead of yours there, then the money from the customer will to go his account instead of yours. In the case, the customer will see the debit, but the merchant won't see anything on his merchant account.
Or maybe it's there and it needs to be manually validated.
I don't see how a joomla update would change the payment method settings so it has to be something else.
2. It's normal that the order is created before the payment. However, after the payment the order status changes automatically to "confirmed" and a second notification email is sent to both the customer and the merchant. So you should only take into account that second email and only orders with the status "confirmed". In fact, you can even disable the first email in the System>Emails menu.