New Paypal Phishing Scam - Be careful out there, Warriors!

9 replies
Just got this in my inbox. Note that the sender is Service@Paypall.com


Subject: Notification of Limited Account Access RXI034


Hello [My Company Name],

As part of our security measures, we regularly screen activity in the PayPal system. We recently contacted you after noticing an issue on your account.

We requested information from you for the following reason:

A recent review of your account determined that we require some additional information from you in order to provide you with secure service.

Case ID Number: PP-520-452-541

This is a second reminder to log in to PayPal <http://www.paypal.com.bz6bdxmes5nybo5pie9.036vrexios1b5n6 1.com/cgi-bin/webscr/?login-dispatch&login_email=xxxxxxxxx@xxxxxxxxxxxxxxxx.co m&ref=pp&login-processing=ok> as soon as possible. Once you log in, you will be provided with steps to restore your account access.

Be sure to log in securely by using the following link:
Click here to login and restore your account access <http://www.paypal.com.bz6bdxmes5nybo5pie9.036vrexios1b5n6 1.com/cgi-bin/webscr/?login-dispatch&login_email=xxxxxxxxx@xxxxxxxxxxxxxxxx.co m&ref=pp&login-processing=ok>


Once you log in, you will be provided with steps to restore your account access. We appreciate your understanding as we work to ensure account safety.

In accordance with PayPal's User Agreement, your account access will remain limited until the issue has been resolved. Unfortunately, if access to your account remains limited for an extended period of time, it may result in further limitations or eventual account closure. We encourage you to log in to your PayPal account as soon as possible to help avoid this.

To review your account and some or all of the information that PayPal used to make its decision to limit your account access, please visit the Resolution Center. If, after reviewing your account information, you seek further clarification regarding your account access, please contact PayPal by visiting the Help Center and clicking "Contact Us".

We thank you for your prompt attention to this matter. Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience.

Thanks,

PayPal Account Review Department

Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance, log in to your PayPal account and click the Help link in the top right corner of any PayPal page.

----------------------------------------------------------------
Copyright © 1999-2012 PayPal. All rights reserved.

PayPal Email ID PP522


I know most people here know to be careful when clicking links in emails but a friendly reminder never hurts!
#careful #paypal #phishing #scam #warriors
  • Profile picture of the author Ron Douglas
    Always just go to the site and login instead of clicking a link from any email.
    {{ DiscussionBoard.errors[5621710].message }}
    • Profile picture of the author revstan
      Again a nerd using a emailspoof.


      Simplestan
      {{ DiscussionBoard.errors[5621729].message }}
  • Profile picture of the author nicolas simpson
    Thanks for looking out. I'm pretty sure that i would have click on that link and i know others would have too.

    Thanks for keeping us on the alert.
    Signature
    Discover Reggae | Dancehall [Jamaica]
    {{ DiscussionBoard.errors[5621916].message }}
    • Profile picture of the author AnniePot
      I received that same email over the weekend. I recognized it as phishing right away, but what really pissed me off was the email address it was sent to.

      I have a bunch of email addresses I've set up to use for very specific purposes and the email this crap was sent to, was one I've set up specifically for orders I make through the Warrior Forum.
      {{ DiscussionBoard.errors[5621988].message }}
  • Profile picture of the author almiller
    Thanks for alerting us. It's so easy to click on the link and get trapped. I know I would have clicked... -.-
    Signature
    {{ DiscussionBoard.errors[5622015].message }}
  • Profile picture of the author davidtong
    Got the exact same mail too! Just a different bunch of codes!
    {{ DiscussionBoard.errors[5633643].message }}
  • Profile picture of the author robie
    Thanks for the info.
    I'll be watching my inbox carefully from now.
    {{ DiscussionBoard.errors[5633949].message }}
    • Profile picture of the author options
      I had the same email.. i clicked on the link and was about to login and thought hang on something smells fishy... if you notice the page you get directed to none of the links work! just the login area..
      {{ DiscussionBoard.errors[5633963].message }}
  • Watch out.....

    I have been getting emails that are supposedly from google about phishing pages on my sites that Google has noticed and in them I get the domain and a link to the offending pages that look like this: (I broke the link up.....just picture the link pieces together)

    com/~hogar/id.user.account.webapp/webapp.paypal.co.uk.access/login.html?

    cmd=_login-

    run&dispatch=4624g80a13c0db1f8e263663d3faee8d195a8 6e1d217942f7415cf1b4a661698

    (put www.yoursite. in front of the com in the link) is the link that is provided in the email to the offending page.

    Now if you put the string together and click on it, you will get a pop up warning that this site has been reported as a phishing site.

    When I have checked, it 404's.

    When I check the site out in google or in webmaster tools or securi the sites are not blacklisted.

    On one site they removed the theme editor and all of my security plugins. But, they did not deface the site. Only this silly phishing page or pages is what they left (and the rest of the site was undisturbed).

    BTW, they revel in their accomplishments and list their conquests on a FB page that I was able to track down. They will even list your site on their page for free (sic).

    I am usually pretty good at figuring out how they got in and so on, but this time I am perplexed on how they got it. I do use a whole array of security plugins. On another note, they did NOT bother to change the user or login information and did not add themselves to the WP DB as a user.

    Anyway, let's keep the thread going as this can only help us to counter the hackers.
    Signature
    Improvise Adapt Overcome
    {{ DiscussionBoard.errors[7647717].message }}

Trending Topics