Skip to content

Comment on PayPal phishing scam coming from paypal.com domainparent

Comments

Oh wow, I would perhaps have expected that email to include some kind of "message from seller: / company: " type subject to at least identify it as such.

For anyone to just be able to send an email in the name of paypal.com with no indication that it was initiated by another paypal user is pretty bonkers.

I haven't seen this before, so either they have very good scam / spam detection or I was just lucky not to have been targeted yet.

I would perhaps have expected that email to include some kind of "message from seller: / company: " type subject to at least identify it as such.

This is the real/root issue. I've seen a few of these and the email itself contains no identifying information which increases the phishing risk/suspicion substantially. Both PayPal, and some banks still send emails with buttons like "confirm your account" - it's wild.

And in fact, it should come from some kind of subdomain like "user-service@random-users-can-send-whatever-they-want-from-this-address.paypal.com" and then the header should be "THIS ISN'T AN OFFICIAL PAYPAL EMAIL" etc. etc.

I wouldn't fall for this scam, because I'm technically minded, but a less technical relative wouldn't stand a chance here.

The messages from PayPal usually do include that sort of "message from seller". The phishers word these to deliberately exploit the issue.

The last time I received a message like this it included this message: "Note from [Fraudulent Seller]: Fraud Alert: Didn't make this order? Call at [Fraudulent 800 number]"

And also the message: "Don't recognize this request? Before paying, make sure you recognize this person. Don't engage with this request if you're unsure about it. PayPal won't contact you through a money request."

But, it did come legitimately from service@paypal.com, and was almost certainly the type of issue OP is describing. I'm not sure PayPal can do anything here but rephrase money requests or invoices as "potential" if they don't come from a contact known to the account. (It'd be cool if they did that.)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.