PayPal users beware of holiday phishing scam

The holiday shopping season means more people making more online purchases -- a prime opportunity for phishing scams

With Black Friday quickly approaching, and retailers racing to outdo each other with earlier and earlier deals, it is safe to say that the holiday shopping season has begun. If you're shopping online, though, and paying with PayPal -- be warned. There is a phishing attack targeted just for you.

The holidays come with a dramatic spike in shopping, and nobody appreciates the increase in online commerce more than cyber criminals. While you're preparing for a Thanksgiving celebration of beer and watching the Detroit Lions make a mockery of professional football...Hey, don't judge. You try supporting a team that has been consistently sad for 60 years and see if you aren't a little bitter. Fine. While you're preparing for a traditional Thanksgiving feast and plotting your Black Friday shopping strategy, malware developers are hard at work finding ways to capitalize on the shopping season.

PayPal is established as a leading method of online payments. It is an integral part of eBay purchasing -- a very popular way to acquire gifts during the holiday season, and it is widely accepted as a method of payment by online retailers of all sorts. It makes sense that cyber criminals would try to capitalize on the spike in PayPal transactions to catch naïve or unsuspecting users off guard.

AppRiver's Troy Gill has uncovered just such a scam. "Since so many people use PayPal in conjunction with the impending holiday shopping spree, scammers are looking to take full advantage of unwary consumers. The latest PayPal related scam targets PayPal users via email. Unlike most of the PayPal scams that we have seen in the past that included a link in the body of the message, these have an attached HTML. When the attachment is clicked a Java Script will produce a Phishing page that mimics a legitimate PayPal page. The input information is then sent off to another domain that will make it available for the cybercriminals."

As Gill notes, this attack attempts to dupe victims by using an attachment as opposed to a link. Granted, users should be conditioned to avoid both links and file attachments in suspicious or questionable e-mails, but just switching things up from the normal malicious URL might be enough to snare some unwary users.

Once the attackers have the PayPal credentials entered on the spoofed PayPal page, they can transfer the funds out of the PayPal account, make purchases using the money in the PayPal account, request funds to be sent to the PayPal account, or anything else the legitimate account holder is normally able to do with a PayPal account.

Most avid PayPal customers hopefully know better than to fall for such a thing, but with the holidays and the spike in online shopping comes a deluge of newbies who know enough to use PayPal to make purchases, but aren't seasoned in how to protect it.

Gill warns, "During the next few months you should be aware that you will be a broader target for scammers looking to take advantage of your increased purchasing activity. Since most people will be making a far greater number of purchases on their credit cards around the holidays they would be less likely to notice fraudulent activity on their cards."

Just remember the mantra that common sense and cautious skepticism will prevent almost all attacks. Happy Holidays!

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags phishingspamvirusespaypalantispamonline securityshopping

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tony Bradley

PC World (US online)
Show Comments

Father’s Day Gift Guide

Brand Post

Bitdefender 2019

Bitdefender solutions stop attacks before they even begin! Get cybersecurity that 500 MILLION users already have and trust.

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?