
Is "Paypal Anti-Fraud Protection" just a scam?I got a message from Paypal with the subject "Help PayPal to avoid any kind of fraud" but I'm a bit suspicious: is this a legitimate way that Paypal is trying to get my help to avoid online scams, or is it a scam itself? I know what email you received, and you're right, it's a scam. To be more specific, it's a "phishing" attempt by some hackers in Russia to get your Paypal account credentials (login and password) so that they can hack your account. Do ont click on the link, do not react to this message other than to simply delete it! Here's what it explains, reasonably enough: "We have noticed an increasing fraudulent activity recently In order to provide your security and protect you from fraudsters we have introduced a new system of identification that will help us to avoid any kind of fraud or unauthorised access." [Paypal is a US-based company, so its team would have written "unauthorized" with a 'z' not an 's', by the way] The message continues: "To complete your Anti-Fraud Protection, you must click the link below and enter as more information as possible to provide your complete identification and to activate all the features of the new system." They did a good job with the phishing message I received. The return address of the message is "PayPal <service@intl.paypal.x.com>" and if you know your Paypal history, "x.com" was a competitor that it acquired in the early days of the biz. Are they still using the domain? Yes, but only for Paypal labs (did you know that? I didn't!), but still, it's not a ".ru" domain that immediately would tip you off. However, if you were to click on the link that is shown as "https://www.paypal.com/" you'd actually go here: http://secure.paypal.com.session-id2511395470...659240.ssl89.ru/
(I skipped about forty digits to show you the full URL) Ignore all the jazz at the front, ignore the session ID, and just look at the very end of the URL: "ssl89.ru". That's not Paypal, that's not X.com and that's not eBay. It's these delinquents in Russia. As I've said many times before, be vigilant and do not click on links in these sort of message, however legitimate and sensible they may seem.
Help others find this article at Del.icio.us, Digg, Netscape, Reddit, and Stumble Upon
Categorized:
Computer and Internet Basics
(Article 8587)
Tagged: ebay, hacking, paypal, phishing, social engineering, spam, x.com Previous: Is this "Problem: Inaccurate whois information" email legit? Next: How do I connect my iPhone to the Starbucks AT&T wifi Network? Subscribe!
Never miss another useful Q&A article again! Subscribe to AskDaveTaylor with Google Reader. Actually, there is an action that you can take regarding this. Paypal maintains an email address for reporting this sort of thing. It is: spoof@paypal.com All you need do is forward the message on to them. Posted by: Chrystoph at November 5, 2008 5:14 AMI have received similar mails too. Paypal, the real company, always addresses their customers with their name, so if such emails do not do that, it's the first sign of something not being quite ok. I have a lot to say, but ...
I do have a comment, now that you mention it!
|
![]()
Search
Find just the answers you seek from among our 2000+ free tech support articles by using our Lijit search engine.
Help!
Subscribe to
Ask Dave Taylor!
Free Updates!
Sign up and get free weekly updates and special offers on books, seminars, workshops and more.
Articles and Reviews
Auctions and Online Shopping Blogs and RSS Feeds Building Web site traffic Business and Management Cell Phones and Mobile Phones CGI Scripts and Web Site Programming Computer and Internet Basics d) None of the Above HTML and CSS Industry News and Trade Shows Mac OS X Help MySpace, Facebook, Twitter and Social Network Help Pay Per Click (PPC) Search Engine Optimization Shell Script Programming Sony PSP, MP3 Players, Etc. The Writing Business Unix and Linux Help Video Game Tips and Help Windows Help
Recent Entries
Join the List!
Book Links
|