Industry guru Dave Taylor offers free tech support on a wide variety of technical and business topics, including HTML, online advertising, Cascading Style Sheets, Web design, management, Unix, Linux, search engine optimization, online dating, Mac OS X, shell script programming and Microsoft Windows.

Is "Paypal Anti-Fraud Protection" just a scam?

I got a message from Paypal with the subject "Help PayPal to avoid any kind of fraud" but I'm a bit suspicious: is this a legitimate way that Paypal is trying to get my help to avoid online scams, or is it a scam itself?


Dave's Answer:

I know what email you received, and you're right, it's a scam. To be more specific, it's a "phishing" attempt by some hackers in Russia to get your Paypal account credentials (login and password) so that they can hack your account. Do ont click on the link, do not react to this message other than to simply delete it!

Here's what it explains, reasonably enough: "We have noticed an increasing fraudulent activity recently In order to provide your security and protect you from fraudsters we have introduced a new system of identification that will help us to avoid any kind of fraud or unauthorised access."

[Paypal is a US-based company, so its team would have written "unauthorized" with a 'z' not an 's', by the way]

The message continues: "To complete your Anti-Fraud Protection, you must click the link below and enter as more information as possible to provide your complete identification and to activate all the features of the new system."

They did a good job with the phishing message I received. The return address of the message is "PayPal <service@intl.paypal.x.com>" and if you know your Paypal history, "x.com" was a competitor that it acquired in the early days of the biz. Are they still using the domain? Yes, but only for Paypal labs (did you know that? I didn't!), but still, it's not a ".ru" domain that immediately would tip you off.

However, if you were to click on the link that is shown as "https://www.paypal.com/" you'd actually go here:

http://secure.paypal.com.session-id2511395470...659240.ssl89.ru/

(I skipped about forty digits to show you the full URL)

Ignore all the jazz at the front, ignore the session ID, and just look at the very end of the URL: "ssl89.ru". That's not Paypal, that's not X.com and that's not eBay.

It's these delinquents in Russia.

As I've said many times before, be vigilant and do not click on links in these sort of message, however legitimate and sensible they may seem.



Help others find this article at Del.icio.us, Digg, Netscape, Reddit, and Stumble Upon    

Subscribe!

Never miss another useful Q&A article again! Subscribe to AskDaveTaylor with Google Reader.

Comments

Actually, there is an action that you can take regarding this.

Paypal maintains an email address for reporting this sort of thing. It is: spoof@paypal.com

All you need do is forward the message on to them.

Posted by: Chrystoph at November 5, 2008 5:14 AM

I have received similar mails too.

Paypal, the real company, always addresses their customers with their name, so if such emails do not do that, it's the first sign of something not being quite ok.

Posted by: Sigurdur Armannsson at December 7, 2008 12:30 PM

I have a lot to say, but ...
Starbucks coffee cup I have a lot to say, and questions of my own for that matter, but most of all I'd like to say thank you for all your efforts on this Web site by buying you a chai!

I do have a comment, now that you mention it!









Remember personal info?


Please note that I will never send you any unsolicited commercial email. Ever.

While I'm at it, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site.









Uniblue: Free Virus Scan

Search
Find just the answers you seek from among our 2000+ free tech support articles by using our Lijit search engine.


Help!





Subscribe to
Ask Dave Taylor!

Add to Google Reader
Add to My Yahoo!
Subscribe in NewsGator Online

RDF   XML

Free Updates!
Sign up and get free weekly updates and special offers on books, seminars, workshops and more.


Recent Entries
Join the List!
Join my author info mailing list, where you'll learn about my upcoming books, speaking gigs, and more!


Book Links
© 2002 - 2009 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site.

[whiteboard marker tray]
"Ask Dave Taylor®" is a registered trademark of Intuitive Systems, LLC.