Thursday, August 18, 2022 12:00 PM

PayPal phishing scam alert

in Science and Technology by MegaBearsFan
Share
submit to reddit
Pin it

I came across an interesting new phishing scam in my personal inbox earlier this week. The scam came in the form of an email from ... paypal.com ... ?

Yep, that's right! I received an invoice from service@paypal.com requesting that I pay a sum of $600 for a gift card for someone who I have never heard of.

This caught me off guard at first. Obviously, I hadn't bought a $600 gift card for a complete stranger, so I suspected phishing right out of the gate. But for a phishing attack like this, I would normally expect the email to come from some random email made up of alphabet soup and coming from a clearly illegitimate domain, and for all the links in the email to refer to similarly illegitimate addresses. But that wasn't the case. The email came from PayPal, and all the buttons and links referred to pages in the PayPal domain. This email looked like a legitimate invoice from PayPal.

I received this email invoice from service@paypal.com, and all the links go to pages in the PayPal domain.

Turns out, it is a legitimate invoice from PayPal! Well, sort of. It is "Legitimate" in the sense that it actually came from PayPal. It is not "legitimate" in the sense that I did not actually buy the thing, nor did I actually owe the money.

After doing a bit of research, I found that this particular scam has been happening since at least 2020, but has been gaining popularity in the past couple months. Basically, the scammers take advantage of a legitimate feature of PayPal, which is the ability for any PayPal user to send an invoice for payment to any other PayPal user. The invoice is, thus, very real. In fact, if the target logs into your actual PayPal account, you might see the invoice there as well, which grants an extra illusion of authenticity to the scam, and might scare people into thinking that they actually owe the money (especially if the email threatens penalties for not paying immediately).

The email actually came from PayPal's domain!

When I logged in, I did not see the invoice in my PayPal account. I believe the reason for this is because this particular invoice was sent out to a group of PayPal users. The others reported it to PayPal as phishing, and so PayPal had probably already removed the fraudulent invoice by the time I had logged in to check it for myself. I even received some of these other user's confused replies directly into my personal email inbox.

This scam relies on the target clicking the link (or logging into their PayPal account) and paying the amount without realizing that it is a fraudulent invoice. If that doesn't work, however, there is a clever backup scam. The emails will usually contain a phone number for either "customer support" or for "cancelling the payment". Since the email actually comes from PayPal's domain, and all the other links and buttons on the email are legitimate, the target might be fooled into thinking that the phone number is also legitimate. It isn't.

If you call this phone number, you will likely be greeted by one of the scammers. The person on the other line will pretend to be PayPal support, and will try to get you to give him access to your PayPal account -- probably by asking you to download some kind of screen-sharing application that will also contain a key-logger. If you download the application and type in your password, the "support" on the other line will be able to harvest that password, and log into your account immediately (or any time in the future) and clear out anything in your PayPal wallet, or spend your real money if the account is linked to your checking account or credit card.

For the record, I did not fall for it. I did not click on the links to pay the invoice, nor did I call the number listed in the email. I learned about the phony support number by reading up about this scam online.

I'm posting this blog in the hopes that it warns other people not to click on the link for these fraudulent (but very legitimate-looking) invoices. I hope that none of my readers fall victim to this -- or any -- scam.

Tags:, , , ,

darkwebprogrammer@gmail.com
darkwebprogrammer@gmail.com
02/18/2025 22:02:17 #

darkwebprogrammer@gmail.com or microprogrammerengineering.wordpress.com got me $15000, I am still stunned.

Jeffery Vargas
Jeffery Vargas
07/07/2025 12:59:18 #

Hello to everyone around the globe. I'm Jefferey Vargas from Malta. My girlfriend ended our relationship for seemingly no reason and I came to understand that my financial struggles may have contributed to this as a healthy relationship is difficult without money and aside from God, having more money is often seen as vital. For spellcasting, Lord Meduza is the right person to turn to. My girlfriend left me for another man due to my financial situation, but after connecting with Lord Meduza, he created a spell that not only brought my girlfriend back but also made me a lottery winner of €116 million by providing me with the 6 lucky numbers. Everything feels almost unreal but I assure you this is genuine and it's occurring. My life is incredibly beautiful and I owe my deepest appreciation to Lord Meduza as his efforts are the epitome of excellence. I strongly encourage everyone here to reach him for help via email: lordmeduzatemple@hotmail.com or you WhatsApp this number +1 (807) 907-2687.

Contribute Comment

avatar


We'll incarnate your avatar from the services below.
PlayStation Network Steam Xbox LIVE Facebook MySpace Pinterest Twitter YouTube deviantART LiveJournal



biuquote
  • Comment
  • Preview


Grid Clock Widget
12      60
11      55
10      50
09      45
08      40
07      35
06      30
05      25
04      20
03      15
02      10
01      05
Grid Clock provided by trowaSoft.

A gamer's thoughts

Welcome to Mega Bears Fan's blog, and thanks for visiting! This blog is mostly dedicated to game reviews, strategies, and analysis of my favorite games. I also talk about my other interests, like football, science and technology, movies, and so on. Feel free to read more about the blog.

Check out my YouTube content at YouTube.com/MegaBearsFan.

Follow me on Twitter at: twitter.com/MegaBearsFan

Patreon

If you enjoy my content, please consider Supporting me on Patreon:
Patreon.com/MegaBearsFan

FTC guidelines require me to disclose that as an Amazon Associate, I earn from qualifying purchases made by clicking on Amazon product links on this site. All Amazon Associate links are for products relevant to the given blog post, and are usually posted because I recommend the product.

Without Gravity

And check out my colleague, David Pax's novel Without Gravity on his website!

Featured Post

Exploring strange new ludic genres of Star Trek (on Patreon)Exploring strange new ludic genres of Star Trek (on Patreon)09/08/2025 2 years ago, after playing both Star Trek: Resurgence and Star Trek: Infinite, I started thinking about how the ludic genres of "point-and-click"-style adventure games and grand strategy games are both very good ludic genres for the Star Trek IP. I had originally planned on creating a short, 20-30 minute video talking about...

Random Post

Where is the "discovering" in Star Trek: Discovery?Where is the "discovering" in Star Trek: Discovery?01/31/2018 I finally got around to watching the entire first half of the first season of CBS's Star Trek: Discovery series. I'm running behind on this show since I don't have a CBS All Access subscription. I've been deliberately avoiding information about the post-hiatus episodes, so information and opinions in this post may be outdated...

Month List