Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsNew PayPal Scam Sends Verified Invoices With Fake Support Numbers
New PayPal Scam Sends Verified Invoices With Fake Support Numbers
Cybersecurity

New PayPal Scam Sends Verified Invoices With Fake Support Numbers

•January 15, 2026
0
HackRead
HackRead•Jan 15, 2026

Companies Mentioned

PayPal

PayPal

PYPL

Google

Google

GOOG

Why It Matters

The scheme demonstrates that even authenticated, platform‑generated messages can be weaponized, raising the threat level for businesses that rely on PayPal for transactions. It underscores the need for stricter verification processes and user education to prevent costly credential theft and remote‑access fraud.

Key Takeaways

  • •Scammers send PayPal invoices with legitimate blue tick
  • •Invoice note includes fraudulent support phone number
  • •Attack bypasses SPF/DKIM/DMARC, evading filters
  • •Victims may grant remote access via call
  • •Report to PayPal and avoid clicking links

Pulse Analysis

The latest PayPal scam leverages the service’s own Money Request and Invoice tools, allowing fraudsters to generate emails that carry the brand’s blue BIMI tick. Because the messages originate from PayPal’s servers, they satisfy SPF, DKIM and DMARC authentication, slipping past corporate spam filters and landing directly in users’ inboxes. The deceptive "Note to Customer" field is where the attackers embed a counterfeit support number, turning a seemingly harmless invoice into a gateway for social engineering.

Once a victim dials the fake number, scammers employ classic callback phishing tactics. They may request remote‑desktop tools such as AnyDesk or TeamViewer, coax the user into revealing login credentials, or convince them to reverse a non‑existent charge by sending funds to a criminal‑controlled account. The FBI has issued alerts about this method, noting its effectiveness in bypassing email‑based defenses and exploiting the trust users place in official communications. The phone call adds a human element that often overrides caution, making the attack more persuasive than a simple malicious link.

Mitigation requires a layered approach: never click links or call numbers embedded in unsolicited invoices, and always verify transactions by logging into PayPal directly. Organizations should educate employees about the limits of visual cues like the blue tick and enforce policies for reporting suspicious invoices. PayPal’s rapid response—removing the invoice and flagging it with a warning—shows the platform’s commitment to fraud detection, yet the incident signals a broader shift where attackers weaponize legitimate services. Strengthening user awareness and enhancing real‑time verification can reduce exposure to this evolving threat vector.

New PayPal Scam Sends Verified Invoices With Fake Support Numbers

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...