I have a PayPal account, so when I received the following email yesterday, it concerned me enough that I decided to log on to PayPal to find out more about this unauthorized change to my account:
You’ve added an additional email address to your PayPal account.
If you don.t agree with this email tcgrady@cox.net [1] and if you need assistance with your account,
please click here to login to your account.
To make sure you can use your PayPal account the next time you make a purchase,
all you need to do is confirm or not your email address.
If your email program has problems with hypertext links,
you may also confirm your email address by logging in to your account.
Thank you for using PayPal!
The PayPal Team
—————————————————————-
Please do not reply to this email. This mailbox is not monitored and you will not receive a response.
For assistance, log in to your PayPal account and click the Help link located in the top right corner of any PayPal page.
This email is great bait. After all, it causes urgency in that the recipient will want to find out who the hell is adding an “additional email address” to PayPal. To find out, I first clicked on the link on the email to get to my PayPal account. I was taken to this fraudulent site [2].
[THIS ABOVE SITE IS FRAUDULENT–DON’T USE IT! Notice the difference between the fraudulent site’s URL and PayPal’s actual URL: https://www.paypal.com/ [3]. If the site doesn’t start off with “paypal” immediately following www, beware.]
The fraudulent PayPal site (which was an elaborate replica of the real PayPal site) immediately asked me to log in by keying in my credit card number, security code and other confidential information (no, I didn’t provide any of that information). If you dig around enough on the fake site, though, you’ll see that many of the links are broken.
This criminal attempt was carefully concocted so that it looked an awful lot like the legitimate PayPal site. It makes me wonder how many people responded to this manipulative email by handing private confidential information to the criminals.
PayPal is quite familiar with this problem [4]:
What is Phishing?
Phishing is a form of fraud designed to steal your identity. It works by using false pretenses to get you to disclose sensitive personal information, such as credit and debit card numbers, account passwords, or Social Security numbers.
One of the most common phishing scams involves sending a fraudulent email that claims to be from a well-known company. Phishing can also be carried out in person, over the phone, through fraudulent pop-up windows, and websites.
DEFINITIONS
Phishing (pronounced “fishing”): Fraudulent emails that request or initiate a scam to get sensitive personal information.
Spoof Site: Fraudulent sites – usually linked from a phishing email – that look like well-known websites.
Print this post [5]
