Reportboom
  • AI Artificial Intelligence
  • AWS
  • Cyber Security
  • Technology
  • Tutorial
  • Cyber Security Jobs
No Result
View All Result
Reportboom
  • AI Artificial Intelligence
  • AWS
  • Cyber Security
  • Technology
  • Tutorial
  • Cyber Security Jobs
No Result
View All Result
Reportboom
No Result
View All Result
PayPal Scam Alert: How Fake Emails Trick Users into Trouble

PayPal Scam Alert: How Fake Emails Trick Users into Trouble

by Cyber Security Team
February 23, 2025
in Cybersecurity
0
Share on FacebookShare on Twitter

A new phishing scam is exploiting PayPal’s address settings to send fraudulent purchase confirmations, tricking users into contacting scammers who attempt to gain remote access to their devices.

How the PayPal Email Scam Works

For the past month, numerous PayPal users have received emails with the subject line: “You added a new address.” The message confirms an address update and includes a fake purchase confirmation for a MacBook M4, urging recipients to call a provided number if they did not authorize the transaction.

You might also like

Japanese Teen Uses ChatGPT to Hack Rakuten, Sells eSIMs for 7.5 Million Yen

Japanese Teen Uses ChatGPT to Hack Rakuten, Sells eSIMs for 7.5 Million Yen

March 6, 2025
Apple has stopped offering end-to-end encrypted iCloud backups in the UK due to a legal order.

Apple appeals UK government demand for iCloud backdoor

March 5, 2025

The scam email typically states:

“Confirmation: Your shipping address for the MacBook M4 Max 1TB ($1,098.95) has been changed. If you did not authorize this update, please reach out to PayPal at +1-888-668-2508.”

These emails originate directly from [email protected], leading many recipients to believe their account has been compromised. However, recipients who checked their PayPal accounts found that no new addresses had been added. In some cases, the emails were even sent to users without a PayPal account.

Why These Phishing Emails Bypass Security Filters

Because these emails come from PayPal’s legitimate email server, they easily pass security and spam filters. The scammers exploit PayPal’s gift address feature, which allows users to add alternative shipping addresses to their profile. By inserting the phishing message into the Address 2 field of a PayPal account, the fraudsters trigger an official PayPal confirmation email containing the scam message.

The Scam’s Ultimate Goal

The primary objective of this scam is to create panic. Once a victim calls the fake PayPal support number, they are:

  • Greeted by an automated PayPal customer service recording.
  • Connected to a scammer posing as a PayPal representative.
  • Instructed to download remote-access software under the pretense of securing their account.

The scammer then directs victims to a malicious website, pplassist[.]com, where they must enter a code that downloads ConnectWise ScreenConnect, granting remote access to their device. Once inside, the fraudster may:

  • Steal banking credentials.
  • Install malware.
  • Extract personal data.

How Scammers Send These Emails

Investigations into the email headers revealed a forwarding mechanism:

  1. The scammer registers a PayPal account and adds a fraudulent address with a fake purchase message.
  2. PayPal sends an official email to the scammer’s address.
  3. That email is auto-forwarded to a Microsoft 365 tenant mailing list, distributing it to multiple targets.

How to Stay Safe

Got one of these emails? Here’s what to do:

  1. Don’t call the number. It’s a scam line, not PayPal.
  2. Log into your PayPal account directly—type paypal.com into your browser.
  3. Check your address list. No changes? Trash the email.
  4. Report the phishing email to PayPal at [email protected].

What PayPal Needs to Do

To mitigate such scams, PayPal should:

  • Limit character count in address form fields to prevent message injection.
  • Strengthen email security policies to block suspicious forwarding.

This scam highlights a growing trend in phishing tactics, where cybercriminals manipulate trusted platforms to exploit users. Always verify suspicious emails directly through your PayPal account and remain vigilant against unsolicited purchase confirmations.

Related Stories

Japanese Teen Uses ChatGPT to Hack Rakuten, Sells eSIMs for 7.5 Million Yen

Japanese Teen Uses ChatGPT to Hack Rakuten, Sells eSIMs for 7.5 Million Yen

by SwiftOnSecurity
March 6, 2025
0

In Japan, police recently arrested three teenagers—aged 14 to 16—for using an artificial intelligence tool called ChatGPT to break into...

Apple has stopped offering end-to-end encrypted iCloud backups in the UK due to a legal order.

Apple appeals UK government demand for iCloud backdoor

by Brian Krebs
March 5, 2025
0

Apple, the tech giant, is pushing back against a request from the UK government. The government wants Apple to create...

Social Media Faces Record Cyber Attacks in Late 2024

Social Media Faces Record Cyber Attacks in Late 2024

by Chris Eng
March 5, 2025
0

In the last few months of 2024, cyberattacks hit an all-time high. A report says 2.55 billion attacks were stopped,...

Cisco Webex Security Flaw Could Expose User Credentials – Here’s How to Stay Safe

Cisco Webex Security Flaw Could Expose User Credentials – Here’s How to Stay Safe

by Jay Peters
March 4, 2025
0

A recently discovered vulnerability in Cisco Webex for BroadWorks could expose user credentials, potentially allowing attackers to impersonate users. While...

Next Post
UK’s iCloud Backdoor Demand: A Threat to Privacy and Security?

UK's iCloud Backdoor Demand: A Threat to Privacy and Security?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

REPORTBOOM

ReportBoom is a premier news portal dedicated to providing the latest and most insightful news in the realms of cybersecurity, technology, artificial intelligence.

  • Home
  • About Us
  • Contact
  • Correction Policy
  • DNPA Code of Ethics
  • Privacy Policy
  • RSS Terms of Use
  • Terms and Conditions

© 2024 - 2025 Reportboom Cosmos Group.

No Result
View All Result
  • AI Artificial Intelligence
  • AWS
  • Cyber Security
  • Technology
  • Tutorial
  • Cyber Security Jobs

© 2024 - 2025 Reportboom Cosmos Group.