Ancestors

Toot

Written by Dave Holland on 2024-12-18 at 02:52

I am getting a number of bogus emails, purporting to be from PayPal. The email address looks credible (service@paypal.com). There are a number of links in it, including “report this Invoice” and “learn to identify phishing”. The “To:” address looks dodgy.

Have checked my account and there has been no activity for ages but have removed my credit card just in case.

[#]PayPal #Scam #Warning

=> View attached media

=> More informations about this toot | More toots from TasDave@aus.social

Descendants

Written by Brandon on 2024-12-18 at 02:58

@TasDave They’re not bypassing PayPal SPF/DKIM (I checked, their dmarc record is up and strict), they’re probably using a compromised user account to send the invoices which means PayPal is treating it as legitimate and it’s coming from the real PayPal, just a hacked account. 2FA saves

Forward to phishing(at)paypal.com and move on?

May be worth checking https://haveibeenpwned.com

=> More informations about this toot | More toots from be_far@treehouse.systems

Written by Dave Holland on 2024-12-18 at 03:35

@be_far

Thanks for that. Will do.

=> More informations about this toot | More toots from TasDave@aus.social

Written by Dave Holland on 2024-12-18 at 03:47

@be_far@treehouse.

I forgot that I had erased the emails. I checked with haveibeenpawned and their was only old stuff that I was aware of. I use a combination of a VPN, Dashlane (and their monitoring services) and DuckDuckGo, and don’t often get anything except broadcast phishing emails. I will forward any more to Paypal but there haven’t been any log ins for months.

Thanks again.

=> More informations about this toot | More toots from TasDave@aus.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113671560269686805
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
258.223645 milliseconds
Gemini-to-HTML Time
1.378835 milliseconds

This content has been proxied by September (ba2dc).