Beware: PayPal “New Address” feature abused to send phishing emails

Beware: PayPal “New Address” feature abused to send phishing emails
Summary: A PayPal email scam is deceiving users into thinking their accounts have been compromised by sending fraudulent purchase notifications. The scam exploits PayPal’s address settings, tricking recipients into calling scammer-operated numbers and granting them remote access to their devices. It is essential for users to verify their accounts directly through PayPal rather than responding to or calling the provided phone numbers in the emails.

Affected: PayPal users

Keypoints :

  • Scammers send fake emails from a legitimate PayPal address, making them seem authentic.
  • The emails falsely claim that a new shipping address has been added and that a purchase was made.
  • Users are tricked into calling a scammer’s number, where they are pressured to download software that allows remote access to their devices.
  • The scam is enabled by a loophole in PayPal’s address settings, which can be exploited by threat actors.

Source: https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/

Views: 13