• Home
  • About Us
  • Services
    • Global Risk Intelligence
    • Trust & Safety
  • Resources
  • Contact Us
  • Home
  • About Us
  • Services
    • Global Risk Intelligence
    • Trust & Safety
  • Resources
  • Contact Us
Home Global Current Affairs

PayPal phishing scam links accounts to fraud

Arpita Roy by Arpita Roy
January 11, 2025
in Global Current Affairs
Reading Time: 2 mins read
3
PayPal phishing scam links accounts to fraud
16
VIEWS
Share on FacebookShare on TwitterLinkedinWhatsapp

A new phishing scam targeting PayPal users has been identified by Fortinet’s FortiGuard Labs. The scam exploits PayPal’s system to trick users into linking their accounts to unauthorized addresses. Using genuine-looking emails and valid login pages, scammers bypass traditional phishing detection methods, posing significant risks to victims’ financial accounts. Fortinet’s CISO, Carl Windsor, highlights the importance of cybersecurity awareness in combating such threats.

The attack leverages Microsoft365’s Sender Rewriting Scheme (SRS) to send legitimate PayPal money requests that pass email authentication checks. Scammers create a Microsoft365 test domain and distribution lists with victim emails, then use PayPal’s money request feature to initiate the attack. Once users log into PayPal through the fraudulent request, their accounts are linked to the scammer’s account, granting them unauthorized access.

This phishing method is particularly deceptive because it uses entirely valid email addresses, URLs, and PayPal login pages, which are typically signs of legitimacy. Users may unwittingly compromise their accounts by acting on the scam’s requests. Windsor emphasizes the need for vigilance, advising users to avoid unsolicited emails, hover over links to verify their authenticity, and never enter login credentials unless certain of a website’s legitimacy.

To enhance protection, enabling two-factor authentication (2FA) on PayPal accounts is highly recommended. Additionally, organizations should train employees to recognize phishing attempts and implement email filtering rules to detect such scams. As cybercriminals continue to innovate, proactive cybersecurity measures and user awareness remain the best defenses against evolving threats.

References

  • New PayPal Phishing Scam Exploits MS365 Tools and Genuine-Looking Emails
  • Phish-free PayPal Phishing
Tags: 2FABreaking NewsCISOCurrent AffairsCyber CrimeCyber ScamCyber SecurityCyber ThreatcybercriminalsCybersecurityemailsFortiGuard LabsFortinetOSINTopediaPayPalPhishingPhishing scamScammerstwo-factor authentication
Arpita Roy

Arpita Roy

A Master’s of Business Administration holder, with a diploma in Interior Designing, and over 10 years of corporate experience in various fields (including Sales, Real Estate, Content Writing, Management, Global Risk Intel, and Operations). Skilled in the field of sales and all types of Internet-based Open Source and Web Intelligence.

Comments 3

  1. Some soldiers and held on the roof Charge ahead of any other way says:
    1 year ago

    Some soldiers and held on the roof Charge ahead of any other way

    Reply
  2. zoritoler imol says:
    1 year ago

    You are a very bright person!

    Reply
  3. binance says:
    10 months ago

    Your point of view caught my eye and was very interesting. Thanks. I have a question for you.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

New York
London
Tel Aviv
Sydney
New Delhi

Mitigating Threats! Intelligence on the Go…

Facebook Twitter Instagram Whatsapp Linkedin Youtube

Company

  • Terms & Conditions
  • Privacy Policy
  • Contact Us

OSINTopedia Infotech Private Limited

Registered under MCA 

contact@osintopedia.com

  • 24.869814, 92.355049

Copyright © 2023   osintopedia.com | Powered by osintopedia.com

OSINTopedia
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
New Letter

hi this is just a sample plz ignore this popup