TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

PayPal phishing scam coming from paypal.com domain

6 pointsby throwaway773854 months ago
I have just received an email from service@paypal.com (yup, that&#x27;s the domain in the email headers, this isn&#x27;t some spoofed name).<p>The email is an obvious phishing attempt, referring to an address change and order I never made. Logging into my PayPal account, everything is unchanged and fine.<p>What I am surprised by is that anyone managed to send an email from service@paypal.com? How is that possible without their DNS being compromised somehow?<p>Someone on Reddit[0] has reported the same and I am wondering if anyone here has noticed &#x2F; whether anyone here works at Paypal and needs to hear about this.<p>[0] https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;paypal&#x2F;comments&#x2F;1ihs0ls&#x2F;getting_tons_of_phishing_emails_from_verified&#x2F;

7 comments

iwanttocomment4 months ago
Anyone can send a money request or invoice to anyone else via PayPal, which will come from PayPal&#x27;s servers and valid PayPal email addresses.<p>I&#x27;m not defending PayPal here, but people can also arbitrarily send a fraudulent invoice to you in email, or via the physical mail, or call you on the phone as well. Fraud of this sort is by no means an issue exclusive to PayPal.<p>You can&#x27;t assume that all communications you receive from PayPal are legitimate requests, in the same way you can&#x27;t assume that all letters or phone calls or text messages you receive are legitimate requests.
评论 #42950777 未加载
评论 #42952024 未加载
litoE4 months ago
I receive them too. They indeed come &quot;From: &lt;service@paypal.com&gt;&quot;, but the dead giveaway is that the recipient is &quot;To: fred smith &lt;order_status10@jwa.onmicrosoft.com&gt;&quot;. I&#x27;m NOT &quot;fred smith&quot; or any of the other random names they use. The emails arrive from the onmicroft.com servers, not the PayPal servers.<p>It looks like they create the fake account at onmicrosoft.com, then have paypal send an email to that account and then make onmicrosoft.com forward it to all their intended victims.
评论 #43004816 未加载
评论 #42952734 未加载
ChrisArchitect4 months ago
Related article:<p><i>Phish-free PayPal Phishing</i><p><a href="https:&#x2F;&#x2F;www.fortinet.com&#x2F;blog&#x2F;threat-research&#x2F;phish-free-paypal-phishing" rel="nofollow">https:&#x2F;&#x2F;www.fortinet.com&#x2F;blog&#x2F;threat-research&#x2F;phish-free-pay...</a>
评论 #42951193 未加载
Meeko4 months ago
This email is for $229.00 purchase of bitcoin from my paypal account. I do not have a paypal account. The sender listed as caitlinrui caitlinrui, Other messaging-service@post.xero.com
beardyw4 months ago
Time was you could send an email purporting to come from anyone. At the time it was just a source of fun. Things are a bit better now, but not much.
pinewurst4 months ago
I deleted my Paypal account after receiving one of these. The convenience was no longer worth the risk for me.
TheBozzCL4 months ago
Are you sure they’re not just spoofing the address? Check the email headers.
评论 #42951130 未加载