Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Monday, August 4, 2008

New Phishing Storm Aimed at PayPal

Today Richard Brewer-Hay, the eBay corporate blogger had a post about PayPal's 10th birthday on eBayInkBlog.

To celebrate the occasion the Phishing crooks & scammers have unleashed a storm of phishing emails.

On July 7th Richard had a post about phishing. I commented at the time,

The simplest, safest and most secure way to put an end to PayPal phishing would be for PayPal to cease putting clickable links in emails. Any customer communication requiring input from customers should be on the secure site.

“You have a message from PayPal which requires response, please log in to your account to access it.”


About three weeks later somebody called Square said,
Henrietta’s suggestion sounds simple enough, but it was already done in the last year and then changed back. I don’t think there was any explanation when it happened or was reversed, I’m guessing that enough sellers, who get tons of these emails and end up click on the transaction link to get more info, complained about the inconvenience. It may be like a safer approach, but it’s also creating an extra step to check on your payments, which is a pain when it multiplies out many times.


I have no knowledge whatsoever of PayPal doing what Square says they did, you would think I might have noticed since last year I was still selling actively on eBay and I accept PayPal on my website, but whatever. Personally I would never, ever, click on a link in an email purported to be from either eBay or PayPal. My advice to you dear reader would be to do the same, send them straight to spoof@paypal.com.

I have received three very high quality and almost believable Phishing communications today. You can see two of them here and here. Links have been disabled!

Giving credit where it is due PayPal responds very fast to reported phishing attempts.
Dear XXX,

Thanks for taking an active role by reporting suspicious-looking emails.
The email you forwarded to us is a phishing email, and our security team
is working to disable it.


Do you have any knowledge of PayPal ending clickable links in email messages last year and then reversing it?

Y'all come back