Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Education Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
PayPal Warns of Ongoing Attacks
Facebook   X   LinkedIn   Email

PayPal Warns of Ongoing Attacks

March 31, 2025

In an article in Forbes, Davey Winder highlights the persistent cyberattacks targeting PayPal users. While these attacks still use tried-and-true tactics for phishing, they also have evolved beyond traditional phishing methods. And they are succeeding. Now they are employing sophisticated techniques that do not necessarily rely on deceptive emails or messages.

One notable method involves credential stuffing attacks. This is when cybercriminals use automated tools to attempt logins on accounts, including PayPal, using credentials obtained from previous data breaches. This tactic exploits the common practice of password reuse across multiple platforms. Once unauthorized access is gained, attackers can initiate unauthorized transactions, potentially leading to significant financial losses for the victims.

Another method is to send user notices that there is a problem with their account. With these, the attackers impersonate PayPal communications to use fear against victims. The intent is that the user will provide information to the attackers so they can take over the account.

The payment request does come from PayPal, so the email may seem legitimate. Even hovering over the Pay Now link will show paypal.com as the true domain. The scammer is sending payment requests from PayPal, so the only way to see it's a scam is by inspecting the payment request itself. Do you know this person? Do you recognize the company or transaction? A quick Google search will give you much more information.

The last one noted are order confirmation scams. In this case, the attacker wants the victim to believe a purchase with the account has been made in a large sum of money. Again, the intent is to steal credentials and take over the account.

It’s also advised to use unique, strong passwords for each online account, not to use passwords across different services, and stay informed about the latest cybersecurity threats.

If you have trouble thinking of hard to guess or crack passwords, try creating a base password of six characters that is a mix of upper- and lower-case letters, numbers, and special characters. Add a few letters from the URL of the website you’re logging into onto the base password. That way, it’s very unlikely you’ll have two passwords that are the same.

In response to these threats, PayPal has implemented several security measures, including multi-factor authentication (MFA) and advanced monitoring systems to detect unusual account activity. The company advises users to enable MFA, as do security experts, regularly update passwords, and remain vigilant spotting suspicious account activity.


Online And Mobile Payment Option Security

Your Security

Online And Mobile Payment Option Security

Most of us have heard of the various payment systems that allow us to pay almost anyone without writing the old-fashioned paper check. Now, we can pay nearly anyone, residing anywhere in the world with just a few taps on the keyboard or touch of an app. The three best known are PayPal, Venmo, and Zelle and all of them are increasingly being used for business purposes. PayPal and Venmo work essentially the same way and are actually owned by the same company, though there are some small differences in how they are used. READ FULL STORY

Avoiding Peer To Peer Payment Scams

Mobile Security

Avoiding Peer To Peer Payment Scams

Peer to Peer (P2P) payment networks like Zelle, PayPal,­ and CashApp have taken the world by storm, and “Pay Yourself” scams are a result. Avoiding these scams means knowing one when you see it, and how to navigate safely around it. These scams are phishing attacks at their foundations, and they typically begin with a scammer impersonating your financial institution. Using email text or phone, their urgent message is about a fraud alert on your account, and they’re here to help. Once you bite, you’ll get a call from the scammer. READ FULL STORY

 53% In U.S. Use Digital Wallets, But Are They Safe?

Mobile Security

53% In U.S. Use Digital Wallets, But Are They Safe?

Digital wallets became a preferred way of paying for purchases since the coronavirus outbreak put them on the map. This easy way of making touch-free, germ-free payments morphed into the method of choice for 53% of shoppers in the U.S., according to a Forbes Advisor survey. But storing credit and other payment cards in a digital wallet raises concerns about the security of these payment apps. Let’s take a closer look so you can decide if using these, such as Apple Pay or Google Pay are a good choice for you. READ FULL STORY

Has Your Account Been Compromised? Five Cyber Smart Tips Everyone Can Use

Your Security

Has Your Account Been Compromised? Five Cyber Smart Tips Everyone Can Use

The transition to living life through our devices has become very real for scores of people and businesses. By now, the coronavirus has changed our lives in ways we never expected. This transition includes doing most things from home. Unfortunately, adapting to online life also gives bad actor’s a cornucopia of targets to exploit. There are proactive steps to take when you suspect an account may be compromised, including ways to help keep it from happening to begin with. READ FULL STORY

Olympic Games Are A Time For Cybercrime Games

Scams & Phishing

Olympic Games Are A Time For Cybercrime Games

There's a big sports-filled event happening over in Paris. You may have heard about the Olympic Games. That means while some are busy cheering on their teams to Olympic gold, cybercriminals are rooting for those same fans to let their guards down and perhaps award them a gold medal instead. All kinds of scams are rampant now, from those involving so-called rare and hard to get merchandise scams to travel-related ones. Here are medal winning tips for avoiding all of them. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...