Interesting PayPal scam

I was surprised yesterday when I received an email from PayPal: “You’ve got a money request”. Wut?

PayPal scam

Not Norton 360!

First thought: duh, it’s a scam. But then I checked the email address it came from: service@paypal.com. Also all of the images in the email came from paypal.com. The links in the email went to paypal.com, together with a randomized-looking, presumably unique, long string to identify yours truly. I even checked the message header: yep, it came from paypal.com.

At the bottom of the email was the usual PayPal text, including “Emails from PayPal will always contain your full name.” I looked up to the start of the email text. Ping! Nope, this one had my email address instead of my name, and furthermore, it was an email address that wasn’t linked to my PayPal account.

In other words, the scam was generated by someone with an actual PayPal account hoping that I’d be flummoxed enough to call that number to get the request cancelled, and in doing so reveal my login info to my personal PayPal account.

Nope.

Gargoyle

Loading similar posts...   Loading links to posts on similar topics...

2 Responses

 avatar
#1 Grzegorz Wiktorowski said...
16-Dec-22 10:46 AM

I'm just scrolling subscribed blogs and just after your post I moved to:

https://daniel.haxx.se/blog/2022/12/14/idn-is-crazy/

Are you under "IDN homograph attack" ?

julian m bucknall avatar
#2 julian m bucknall said...
16-Dec-22 6:57 PM

@Grzegorz: Ha! I'd read about this before, but doesn't apply to this particular email, since it was Google (I use a GMail account for personal email) that authenticated its provenance. The email headers also show that it came from PayPal, referencing their IP address.

Cheers, Julian

Leave a response

Note: some MarkDown is allowed, but HTML is not. Expand to show what's available.

  •  Emphasize with italics: surround word with underscores _emphasis_
  •  Emphasize strongly: surround word with double-asterisks **strong**
  •  Link: surround text with square brackets, url with parentheses [text](url)
  •  Inline code: surround text with backticks `IEnumerable`
  •  Unordered list: start each line with an asterisk, space * an item
  •  Ordered list: start each line with a digit, period, space 1. an item
  •  Insert code block: start each line with four spaces
  •  Insert blockquote: start each line with right-angle-bracket, space > Now is the time...
Preview of response