Paypal Caution: all that use Paypal please read

Computer Parts, Games, DVD's, ex-girfriends..well you get the idea. No dealers, referral links, spam, or auctions. Please be sure your email shows in your profile and to post a price when selling.
User avatar
Executioner
Life Member
Posts: 10351
Joined: Wed Nov 22, 2000 11:34 am
Location: Woodland, CA USA

Paypal Caution: all that use Paypal please read

Post by Executioner »

I received this email, and after carefully looking at it, it looked very legit from Paypal. The purpose of the message was to inform me that I had added another email address, and it was confirming this decision. To verify, I actually logged into Paypal to verify, and it was not added. I sent the email to Paypal, and they confirmed that it was a spoof.

Here is the text of the email:
=========================================

Date: 12 Nov 2005 00:07:59 +0900
To: xxxxxxx@yahoo.com
Subject: New email address added to your PayPal account !
From: service@paypal.com

You have added peter_beggs@yahoo.com as a new email address for your PayPal account.

If you did not authorize this change or if you need assistance with your account, please contact PayPal customer service at:

https://www.paypal.com/us/wf/f=ap_email

Thank you for using PayPal!
The PayPal Team

Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the header of any page.
-----------------------------------------------------------------

PROTECT YOUR PASSWORD

NEVER give your password to anyone and ONLY log in at
https://www.paypal.com/. Protect yourself against fraudulent websites by opening a new web browser (e.g. Internet Explorer or Netscape) and typing in the PayPal URL every time you log in to your account.
-----------------------------------------------------------------

PayPal Email ID PP1037

=========================================
As you can see, it looks pretty legit.

Here is the response from Paypal:

Dear Charlie Wathen,

Thank you for contacting PayPal. We appreciate you bringing this suspicious email to our attention.

Commonly referred to as phishing, these emails are sent by fraudsters in an attempt to collect sensitive personal or financial information from the recipients. PayPal takes phishing threats seriously. Our fraud prevention specialists are working 24/7 to help protect you and enable the community to stay safe.

After review, we can confirm that the email you received was not sent by PayPal. Any website which may be linked to this email is not authorized or used by PayPal.

Our fraud prevention team is working to disable any website linked to this email. In the meantime, please do not enter any information into this website. If you have already done so, you should immediately log into your PayPal account and change your password, as well as your security questions and answers. We also recommend that you contact your bank and credit card company immediately.

If you notice any unauthorized activity on your PayPal account, please report it to us by following the instructions below:

1. Log in to your account only from the PayPal website. Do not use links provided in any email.

2. Click on the Security Center link at the bottom of the page.

3. Click on the 'Unauthorized Transaction' link under the Report a Problem column.

4. Follow the instructions on this page in order to access the appropriate form.

Lastly, we recommend taking a few steps to protect yourself from identity theft:

> Download the SafetyBar, a toolbar for Outlook and Outlook Express, which identifies known spoof emails.
> Get eBay Toolbar with Account Guard which warns you when you're on a potentially fraudulent (spoof) Web site.
> Frequently monitor your account for suspicious activity.

For additional tips please visit the PayPal Security Center at http://www.paypal.com/security.

Once again, thank you for reporting this suspicious email. Your vigilance helps us in our efforts to protect the PayPal community. If you have any further questions, please feel free to contact us again.

Sincerely,

PayPal
______________________________

Important: PayPal and its representatives will NEVER ask you to reveal your password. There are NO EXCEPTIONS to this policy. If anyone claiming to work for PayPal asks for your password under any circumstances, by email or by phone, please refuse and immediately contact us via our secure webform online.

************************************************************************
This email is sent to you by the contracting entity to your User Agreement, either PayPal Inc or PayPal (Europe) Limited. PayPal(Europe) Limited is authorized and regulated by the Financial Services Authority in the UK
as an electronic money institution.
***********************************************************************
User avatar
DoPeY5007
Almighty Member
Posts: 4259
Joined: Fri Dec 27, 2002 5:50 pm
Location: Moved to the hood, a few blocks from USC
Contact:

Post by DoPeY5007 »

I use outlook for my mail, and I mouse over a link and you can see if it is real or fake.

If you get an e-mail from eBay or PayPal and you may think iti is fake forward it to spoof@paypal.com or spoof@ebay.com eBay will respond back to you telling you if the message was fake or real
Image Image Image

"I'm seriously going to pummel you until you purr like a bitch-kitten!!"
User avatar
dadx2mj
Posts: 4359
Joined: Wed Nov 22, 2000 12:24 pm
Location: So Cal

Post by dadx2mj »

I've been getting that email or one very similar to it for weeks now...funny thing is I have never had a PayPal account.
Image
User avatar
DoPeY5007
Almighty Member
Posts: 4259
Joined: Fri Dec 27, 2002 5:50 pm
Location: Moved to the hood, a few blocks from USC
Contact:

Post by DoPeY5007 »

I just got a chase bank one. I don't have an account with them. Just never click the "Bank" e-mails.
Image Image Image

"I'm seriously going to pummel you until you purr like a bitch-kitten!!"
RubberDuckie
Posts: 2854
Joined: Thu Nov 23, 2000 3:38 am
Location: Texas
Contact:

Post by RubberDuckie »

I personally do not pay any attention to ANY email I did not request.
JSTMF
User avatar
Pugsley
Posts: 7512
Joined: Mon Aug 19, 2002 11:54 pm
Location: NW Indiana
Contact:

Post by Pugsley »

I fill out the forms at the fake sites. this way it just waters down their database with useless info.
[align=center]A self-aware artificial intelligence would suffer from a divide by zero error if it were programmed to be Amish[/align]
User avatar
Gillbot
Posts: 526
Joined: Sun Aug 26, 2001 10:03 am
Location: East Palestine, OH

Post by Gillbot »

If I get any of those emails, I just manually go to https://www.paypal.com and login to check.
Heatware - Gillbot
Blade is DA MAN!!!!!! :D
[SIZE="5"]R.I.P. Mr. Michael Lee Valley
blade, You will be missed. [/size]
Image Image
User avatar
Shadow250
Golden Member
Posts: 1172
Joined: Fri Jan 04, 2002 9:08 pm
Location: Walton New York 13856
Contact:

Post by Shadow250 »

i do what pugsley does sometimes. i write stuff like name: your retarded address: 7734 hells dr.
stuff like that. kinda funny to think of them reading it.
Image

<a href="http://www.heatware.com/eval.php?id=9490"><font color=red>My Heatware<font/></a> <font color=white><font size="2"> :cool

:hic :rockon:
xman1102
Senior Member
Posts: 185
Joined: Tue Jun 11, 2002 10:38 pm

Post by xman1102 »

i've been getting these emails too and at a glance they seem legit. i moused over the link the first time i got one and noticed it wasnt to Paypal. i can definitely see how someone would fall for this...i know my wife would, i had to warn her about these emails.
nutxo
Senior Member
Posts: 160
Joined: Fri Jun 01, 2001 7:54 pm
Location: tacoma

Post by nutxo »

I got an email from paypal a week and a half ago. It said a merchant had compromised my CC and they cancelled it. I called paypal. It was legit and I had to get a new card.
User avatar
rndmtask
Senior Member
Posts: 429
Joined: Mon Feb 23, 2004 10:50 pm

Post by rndmtask »

I fill in crap too. but crap that looks legitimate. That really waters down the database and if everyone who knew what was going on did that then we would be good. But the link in that email you posted goes to the real paypal. Did you fix it to be right or is that the real place it sent you?
User avatar
wpublic
Senior Member
Posts: 350
Joined: Sun Jan 06, 2002 6:07 am
Location: nashville, tn

Post by wpublic »

those emails usually are html with images and links pointing to the real bank or paypal site. all except for one link in the middle where you click.

then the dummy page you go to all have the same links pointing to the legit site except for the form/post function which hides the true recepient in a .js file. get the .js file and you will see where the info is going. usually to a free email account that is checked by someone behind an anonymous proxy where they get your stuff and sell it.

you can usually see the real IP of the dummy page. usually a school system or small ISP in SE asia, but i have seen them from anywhere someone can remotely set up a web server without the admins catching quickly. these pages can usually get shut down quickly by reporting to their domain admins, but they don't care if those pages get shut down, another will just poop out somewhere else and the damage has already been done.

this type of fraud is an industry and more organized than some might think. the best way to get them is giving them BS info. many, many times. then the person won't just lose business selling all your CC infos, they would probably get their head cracked by the types they deal with.

at the least, they would know not to send emails to you anymore.
User avatar
DoPeY5007
Almighty Member
Posts: 4259
Joined: Fri Dec 27, 2002 5:50 pm
Location: Moved to the hood, a few blocks from USC
Contact:

Post by DoPeY5007 »

Originally posted by rndmtask
But the link in that email you posted goes to the real paypal. Did you fix it to be right or is that the real place it sent you?
That is because he did a copy and past, the hidden link was in the HTML that didn't come over to the forum
Image Image Image

"I'm seriously going to pummel you until you purr like a bitch-kitten!!"
User avatar
rndmtask
Senior Member
Posts: 429
Joined: Mon Feb 23, 2004 10:50 pm

Post by rndmtask »

Originally posted by DoPeY5007
That is because he did a copy and past, the hidden link was in the HTML that didn't come over to the forum


Thought so. The reason I don't fill them out multiple times is I figure they're smart enough to realize 20 people don't share the same cable modem IP.
bigdaddy51
Genuine Member
Posts: 35
Joined: Mon Nov 28, 2005 6:58 pm
Location: StaffordSprings Ct.

Post by bigdaddy51 »

Quick note any legit paypal communication will refer to you by name, NOT dear customer etc. I get at least 2 a week
BIGDADDYS GOLDEN RULE, "NEVER BUY A VERSION 1 ANYTHING."
Post Reply