With e-commerce scams increasing over the Christmas period, many consumers turn to payment provider PayPal to make their shopping experience safer online.

PayPal is commonly regarded as a safe platform which treats security and strong encryption as key priorities; however, this could be set to change as a new and advanced phishing scam is targeting PayPal users to steal large amounts of money and personal information.

The Phishing Email

According to users who have been affected by this scam, the phishing email is sent from a legitimate-looking PayPal email address, “service@paypal.com“. The fact that these scams are coming from legitimate email addresses makes this scam even more dangerous than other common phishing emails.

Typically phishing emails will be sent from email addresses that resemble legitimate corporate accounts, but actually have minor spelling errors (One common fake address used by scammers is service@liinkedin.com). Scammers rely on victims being pressured or careless when reading the email and failing to notice the error.

Fortunately, even though the sender’s address does not contain any errors, reports from victims state that the email itself is riddled with spelling mistakes and poor grammar. These are common signs of phishing emails and provided a user has had adequate security awareness training, they shouldn’t be fooled into making a payment or clicking on any links.

The PayPal phishing emails also include wording that encourages their target victims to act quickly or be charged a large amount of money by the payment platform (most of the emails refer to an amount of around £887). This is another sign of a phishing email, the use of urgent or emotional language. Again, provided that a user has received adequate training to recognise a phishing scam, this use of language should be a helpful sign not to take any action requested in the email.

The ‘One-Ring’ Scam

These scam emails also feature a support phone number. While it claims that the number can be called free of charge for help with the issue mentioned, the number is actually an international phone number, which if called, would trigger a vishing attack.

Vishing attacks, while less common than phishing, are much more effective. In 2022, voice-phishing attacks succeeded in getting 53.2% of their targeted victims to click on a malicious link. If a victim of this PayPal scam called the number, it is likely they will speak to the scammer themselves, who will pressure the victim further into making a transaction.

In this case, victims are greeted by a self-declared “customer service representative“, who proceeds to ask prying personal and financial questions to gain enough information to break into their PayPal account, compromise the victim’s identity, or even access other critical accounts, such as their bank account. This is by far the most dangerous part of the scam. If a user releases personal and financial information to scammers directly, then all of their money and data is at risk of being stolen.

In addition to extracting personal information, calling the international number will result in the victim’s phone company charging for making a long-distance call. This means that this PayPal scam carries the double threat of also being a ‘one-ring‘ scam.

How to avoid this scam

The best way to avoid vishing is to never call numbers that you haven’t verified, never give out passwords and personal information over the phone, and always question individuals who ask for such information. It’s not rude to ask a representative of a company why they need to know your bank details or your address, it’s your data and you should treat it like items of personal property.

In fake calls, questions often confuse and fluster scammers, so listen out for any changes in tone or attitude.

As for phishing emails, if you are uncertain whether or not an email is legitimate, contact the company directly, using communication channels you’ve used before, or visit their anti-fraud website, here.

TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
We are currently offering a free service that will help to identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the current best methods of identifying phishing emails: