# Fuck not another Pay Pal scam

**URL:** <https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172>\
**Category:** The BBQ Pit\
**Created:** [May 19, 2003, 3:34am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172 "2003-05-19T03:34:36Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![MannyL](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@MannyL](https://boards.straightdope.com/u/MannyL)\
**Post date:** [May 19, 2003, 3:34am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/1 "2003-05-19T03:34:36Z")

</div>

Man these guys are getting good. I got a nice HTML E-mail that looks like it came from PayPal with the right logos and colors.

The first thing I did was look at the header and to me it looked legit as it seemed to come from Pay Pal and did not go though mutiple mail servers as far as I saw.

Return-Path: \<[paysecurity@paypal.com](mailto:paysecurity@paypal.com)\>  
Delivered-To: --my address removed–  
Received: (cpmta 5954 invoked from network); 18 May 2003 20:08:30 -0700  
Received: from 62.218.123.2 (HELO [compuserve.com](http://compuserve.com))  
by [smtp.c000.snv.cp.net](http://smtp.c000.snv.cp.net) (209.228.32.61) with SMTP; 18 May 2003 20:08:30 -0700  
X-Received: 19 May 2003 03:08:30 GMT  
Date: Mon, 19 May 2003 02:23:22 +0000  
From: Paysecurity \<[paysecurity@paypal.com](mailto:paysecurity@paypal.com)\>  
Subject: Dear PayPal Customer!  
To:  
References: \<[0I5A8CF8A022HJKFG@levy.net](mailto:0I5A8CF8A022HJKFG@levy.net)\>  
In-Reply-To: \<[0I5A8CF8A022HJKFG@levy.net](mailto:0I5A8CF8A022HJKFG@levy.net)\>  
Message-ID: \<[GHB339LFB85K.ELBD@paypal.com](mailto:GHB339LFB85K.ELBD@paypal.com)\>  
Sender: Paysecurity \<[paysecurity@paypal.com](mailto:paysecurity@paypal.com)\>  
MIME-Version: 1.0  
Content-Type: multipart/mixed; boundary="----=\_NextPart\_1CD7.CLKGBID5B184D.L6J7\_9"  
Status: U  
X-UIDL: PshKsNHkID0XWwE  
The text of the E-mail which was writting in HTML said

This e-mail is the notification of recent innovations taken by PayPal to detect inactive customers and non-functioning mailboxes.

The inactive customers are subject to restriction and removal in the next 3 months.

Please confirm your email address and and Credit Card info number by logging in to your PayPal account using the form below:

It had boxes to enter the following  
It asked for the following information Email Address:

Password:  
Full Name #:  
Credit Card #:  
Exp.Date(mm/yy) #:  
ATM PIN (For Bank Verification) #:  
The form goes to [http://www.paypal.com@funnygirls.port5.com/pp.php](http://www.paypal.com@funnygirls.port5.com/pp.php) if you click on the submit link it breidly redirects you to [funnyfirls.port5.com](http://funnyfirls.port5.com) then that redirects you to the paypal login page. I have already E-mailed Pay Pal about it. [port5.com](http://port5.com) is an web host out of Surry and funnygirls seems to be a site that have credit reports info

I almost fucking fell for this scam, then I would have had to change my passwords and my bank account and credit card numbers because they would have had access to my information. Why the fuck do people try to pull these scams off?

---

<div class="post-metadata">

**Author:** ![mojave66](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@mojave66](https://boards.straightdope.com/u/mojave66)\
**Post date:** [May 19, 2003, 3:55am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/2 "2003-05-19T03:55:13Z")

</div>

Because it unfortunately works on idiots like me.

About 4 months ago I fell for a similar scam, only they also wanted SSNs along with bank account numbers and all sorts of personal information that I fortunately didn’t give them.

I have to take responsibility on this, I didn’t check the URL to make sure that the site was a legit PayPal site, I just relied on the purty colors. Fortunately for me, they got greedier than my bank account allows.

That being said, PayPal can do a _bit_ more to protect its customers. Like, quite a bit more. There are itty bitty notes at the bottom of PayPal letters that say “be careful.” You’d _think_ they’d want to make it a POINT to tell you, but nooooo…

Plus, it was a massive pain in the nalgas to inform PayPal about what was happening-- “want to make a complaint? Need a password. Missing your password? Need a security code. Security code problems? You need your password.” Kind of difficult to do when ALL your PayPal info has been hijacked.

---

<div class="post-metadata">

**Author:** ![Ringo](https://avatars.discourse-cdn.com/v4/letter/r/779978/32.png) [@Ringo](https://boards.straightdope.com/u/Ringo)\
**Post date:** [May 19, 2003, 3:57am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/3 "2003-05-19T03:57:34Z")

</div>

> [@](#):
>
> Why the fuck do people try to pull these scams off?

That part’s pretty obvious isn’t it? Yes, a pox on these scoundrels!

---

<div class="post-metadata">

**Author:** ![White\_Lightning](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@White\_Lightning](https://boards.straightdope.com/u/White_Lightning)\
**Post date:** [May 19, 2003, 4:47am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/4 "2003-05-19T04:47:09Z")

</div>

You forgot to remove your name and email address in the second instance.

---

<div class="post-metadata">

**Author:** ![MannyL](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@MannyL](https://boards.straightdope.com/u/MannyL)\
**Post date:** [May 19, 2003, 5:40am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/5 "2003-05-19T05:40:00Z")

</div>

Umm double checking it No I didn’t

[0I5A8CF8A022HJKFG@levy.net](mailto:0I5A8CF8A022HJKFG@levy.net) is not my address. [Levy.net](http://Levy.net) part of a company is a company that “rents” E-mail addresses in the namespace they own. You renew your name every year. I have no idea if 0I5A8CF8A022HJKFG is a valid user there, but I doubt someone is going to buy an address that had to remember

---

<div class="post-metadata">

**Author:** ![Tommyturtle](https://avatars.discourse-cdn.com/v4/letter/t/8491ac/32.png) [@Tommyturtle](https://boards.straightdope.com/u/Tommyturtle)\
**Post date:** [May 19, 2003, 6:38am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/6 "2003-05-19T06:38:40Z")

</div>

I once had an auction end and I got an email that LOOKED for all the world like a Paypal email telling me they paid…I however went to Paypal and there was nothing in my accound to show they paid and when I contacted the buyer he never responded.

I guess he took a shot at ripping me off…I reported him to Ebay AND Paypal.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [May 19, 2003, 10:21am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/7 "2003-05-19T10:21:08Z")

</div>

MannyL, I go the exact same email some weeks ago and reported it to paypal but it seems the scam is still going on.

I just don’t understand how people fall for this stuff. I did see the fake paypal return address but, in any case, that’s not the point. No reputable entity is going to ask for your information like that and, if any one does, I’d be closing my account with them. Anyone who falls for this is really very naive.

I am amazed by the gullibility of people. What the hell are they thinking? If you get a phone call from someone saying it is your bank and you need to make a deposit and they will send a guy to pick up the money. . . would you give the guy any money? Does that sound like the way a bank operates? If you think so please email me as I have a proposal for you.

---

<div class="post-metadata">

**Author:** ![White\_Lightning](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@White\_Lightning](https://boards.straightdope.com/u/White_Lightning)\
**Post date:** [May 20, 2003, 10:21pm UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/8 "2003-05-20T22:21:44Z")

</div>

Well, right after I posted I reported it to the mods, so maybe they removed it before you saw it, but it was there. Sorry if I offended you by mentioning it.

> [@](#):
>
> Date: Mon, 19 May 2003 02:23:22 +0000  
> From: Paysecurity \<[paysecurity@paypal.com](mailto:paysecurity@paypal.com)\>  
> Subject: Dear PayPal Customer!  
> To: This is where it was… now this space is blank  
> References: \<[0I5A8CF8A022HJKFG@levy.net](mailto:0I5A8CF8A022HJKFG@levy.net)\>

---

<div class="post-metadata">

**Author:** ![LolaCocaCola](https://avatars.discourse-cdn.com/v4/letter/l/7cd45c/32.png) [@LolaCocaCola](https://boards.straightdope.com/u/LolaCocaCola)\
**Post date:** [May 20, 2003, 10:31pm UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/9 "2003-05-20T22:31:25Z")

</div>

Glad to hear you didn’t fall for it, **Manny**.

---

<div class="post-metadata">

**Author:** ![mojave66](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@mojave66](https://boards.straightdope.com/u/mojave66)\
**Post date:** [May 20, 2003, 11:28pm UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/10 "2003-05-20T23:28:46Z")

</div>

> [@](#):
>
> No reputable entity is going to ask for your information like that and, if any one does, I’d be closing my account with them. Anyone who falls for this is really very naive.

In my defense it was a pretty hectic day plus at the time I had quite a few business transactions flying through PayPal and didn’t want to stall them. I also had NO idea there was a scam going on, and heaven knows PayPal wasn’t being very good about alerting their membership.

But truthfully, I really can’t fob much of the responsibility off on them. I really SHOULD have follwed my gut instinct, which at the time was saying “odd, there’s a lot of info on here I shouldn’t be giving out.” Fortunately there was a lot I _didn’t_ put on the fake form. But I’m an idiot and went ahead and submitted what info I did fill in. Yes, I’m a putz.

---

<div class="post-metadata">

**Author:** ![Freyr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/freyr/32/5763_2.png) [@Freyr](https://boards.straightdope.com/u/Freyr)\
**Post date:** [May 21, 2003, 5:41am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/11 "2003-05-21T05:41:32Z")

</div>

Really weird… I got this bit of spam today, too… check out this note:

> [@](#):
>
> \*\*Dear Paypal Member.
> 
> Your account has been randomly flagged in our system as a part of our routine security measures. This is a must to ensure that only you have access and use of your paypal account and to ensure a safe Paypal experience.
> 
> We require all flagged accounts to verify their information on file with us.
> 
> To verify your information, click here and enter the details requested.
> 
> After you verify your information, your account shall be returned to good standing and you will continue to have full use of your account.
> 
> Thank you for using PayPal!\*\*

I checked the headers and it looks legit, but they’re asking for a LOT of the same information and the link takes me to the PAYPAL site. Does Paypal do this?

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [May 21, 2003, 6:08am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/12 "2003-05-21T06:08:33Z")

</div>

I’d be wary:

> [@](#):
>
> If you receive an email and are unsure whether it is from PayPal, come directly to the PayPal site at [www.paypal.com](http://www.paypal.com). **Don’t click on any link in an email which seems suspicious to you**. These security measures will help ensure that you are logging into PayPal. The only site you should ever type your username and password into is at [www.paypal.com](http://www.paypal.com).

From [Paypal.](http://www.paypal.com/cgi-bin/webscr?cmd=p/gen/fraud-prevention-outside)  
Bolding mine.

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [May 21, 2003, 6:48am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/13 "2003-05-21T06:48:22Z")

</div>

To be safe, close the email, and in your browser, just type in [https://www.paypal.com](https://www.paypal.com) (Note the https indicating a secured site) and go there yourself without using any links.

Freyr, I’d need to see the entire message in HTML to know what’s up. Forms redirects can be surprisingly well-concealed, especially when buried in 300 lines of coding.

Paypal’s security info page is [here](https://www.paypal.com/cgi-bin/webscr?cmd=p/gen/security-main) and includes links for reporting spam and scams.

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [May 21, 2003, 6:50am UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/14 "2003-05-21T06:50:15Z")

</div>

Errr… that link for PayPal’s security only works if you’re logged in. The public page not requiring a login is [here](http://www.paypal.com/cgi-bin/webscr?cmd=p/gen/security-main-outside)

---

<div class="post-metadata">

**Author:** ![Tripler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tripler/32/21807_2.png) [@Tripler](https://boards.straightdope.com/u/Tripler)\
**Post date:** [May 26, 2003, 9:02pm UTC](https://boards.straightdope.com/t/fuck-not-another-pay-pal-scam/176172/15 "2003-05-26T21:02:25Z")

</div>

Whoa. Thanks to you guys I didn’t provide a whole lot of information.

Just to be sure, I closed out my credit card account and put a password on it.

Whoa. . .

Tripler  
I’m in debt enough. I don’t need someone else’s.
