# How does this PayPal payment request scam work?

**URL:** <https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126>\
**Category:** Factual Questions\
**Created:** [December 3, 2024, 5:01pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126 "2024-12-03T17:01:18Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 3, 2024, 5:01pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/1 "2024-12-03T17:01:18Z")

</div>

I got two seemingly unrelated emails today notifying me that I have PayPal payment requests. I do have a PayPal account. There is a link in each email to go to PayPal to make payment. The link is for a [paypal.com](http://paypal.com) URL so on the surface the URL seems legit (the payment request itself is definitely _not_ legit). It prompts me to login, but it does this even if I am already logged in on another tab, which I would not expect. But I’m not going to login to that page just to see what happens in case it’s a clever way of harvesting credentials.

But I can’t figure out the end game here. Are they somehow capturing my credentials? Or are they trying to get me to make a payment? If I just login to PayPal there are no payment requests.

They also both are from different vendors, but in the “Note from ” section they give the same 855 phone number to call. Maybe they are just trying to get me to call the number.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [December 3, 2024, 5:17pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/2 "2024-12-03T17:17:36Z")

</div>

> [@CookingWithGas](#):
>
> But I can’t figure out the end game here. Are they somehow capturing my credentials? Or are they trying to get me to make a payment? If I just login to PayPal there are no payment requests.

Could be either or both. Since you have no payment requests, you can ignore the fraud.

If you are curious about a link, you can use [https://urlscan.io/](https://urlscan.io/) to view a screenshot or use [https://www.browserling.com/](https://www.browserling.com/) to access the site in a sandbox environment.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 3, 2024, 5:41pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/3 "2024-12-03T17:41:37Z")

</div>

> [@CookingWithGas](#):
>
> The link is for a [paypal.com](http://paypal.com) URL

How sure are you of this? Like “IT / web professional” sure, or like “I see the letters `paypal.com` on my screen” sure?

It’s a near certainty the url doesn’t go where you think it does and you’re looking at a credential harvesting scam.

---

<div class="post-metadata">

**Author:** ![md-2000](https://avatars.discourse-cdn.com/v4/letter/m/9d8465/32.png) [@md-2000](https://boards.straightdope.com/u/md-2000)\
**Post date:** [December 3, 2024, 6:42pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/4 "2024-12-03T18:42:09Z")

</div>

A common trick is something like “paypal dot com dot paymentrequirednow dot com” so the words appear there, but don’t go where you think they do. Plus, a string of text can say anything and have a link connected behind it to take you anywhere else.

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [December 3, 2024, 6:50pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/5 "2024-12-03T18:50:10Z")

</div>

Maybe it came from [рayрal.com](http://xn--ayal-f6dc.com).

That’s the Cyrillic re, not the Latin pee

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [December 3, 2024, 7:01pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/6 "2024-12-03T19:01:34Z")

</div>

I got these and I think they are generating an actual PayPal payment request email and then repurposing it for the scam.

What they probably want you to do is to call the help number included in the scam email and that’s when they’ll try and get you. Is there a phony-seeming help number?

I have to admit, these are really well done scams.

ETA: For example, here’s what one of mine says:

Amount requested  
$899.99 USD

Note from Excellens Lawncare:  
Due to a PayPal server problem, we approved a transaction without your permission. We’re sorry for the inconvenience. For a refund, contact PayPal immediately at 1(855) 314-4565.

Transaction ID  
U-1LU62175X6727683K

Transaction date  
November 27, 2024

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [December 3, 2024, 7:05pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/7 "2024-12-03T19:05:08Z")

</div>

No, because when I hover over that, I get nonsense at the bottom of the browser, but when I hover over the links in the email, I get [paypal.com](http://paypal.com).

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 3, 2024, 7:09pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/8 "2024-12-03T19:09:39Z")

</div>

> [@LSLGuy](#):
>
> How sure are you of this?

[https://www.paypal.com/signin/?returnUri=%2Fmyaccount%2Ftransfer%2FpayRequest%2FU-06C88558L1014094C%2FU-2DM00000BR7721433%3FclassicUrl%3D%2FUS%2Fcgi-bin%2F%3Fcmd%3D\_prq&id=Ry38v2FrK0UjF72A307PSNceYxU8e31AX6KM7A&expId=p2p&onboardData={"signUpRequest"%3A{"method"%3A"get"%2C"url"%3A"https%3A%2F%2Fwww.paypal.com%2Fmyaccount%2Ftransfer%2FguestLogin%2FpayRequest%2FU-06C88558L1014094C%2FU-2DM00000BR7721433%3FclassicUrl%3D%2FUS%2Fcgi-bin%2F%3Fcmd%3D\_prq%26id%3DRy38v2FrK0UjF72A307PSNceYxU8e31AX6KM7A"}}&flowContextData=](https://www.paypal.com/signin/?returnUri=%2Fmyaccount%2Ftransfer%2FpayRequest%2FU-06C88558L1014094C%2FU-2DM00000BR7721433%3FclassicUrl%3D%2FUS%2Fcgi-bin%2F%3Fcmd%3D_prq&id=Ry38v2FrK0UjF72A307PSNceYxU8e31AX6KM7A&expId=p2p&onboardData=%7B%22signUpRequest%22%3A%7B%22method%22%3A%22get%22%2C%22url%22%3A%22https%3A%2F%2Fwww.paypal.com%2Fmyaccount%2Ftransfer%2FguestLogin%2FpayRequest%2FU-06C88558L1014094C%2FU-2DM00000BR7721433%3FclassicUrl%3D%2FUS%2Fcgi-bin%2F%3Fcmd%3D_prq%26id%3DRy38v2FrK0UjF72A307PSNceYxU8e31AX6KM7A%22%7D%7D&flowContextData=)**[arg deleted]**&v=1&utm\_source=unp&utm\_medium=email&utm\_campaign=RT000186&utm\_unptid=edc46c96-b18e-11ef-a3e7-1b67a4a59178&ppid=RT000186&cnac=US&rsta=en\_US%28en-US%29&unptid=edc46c96-b18e-11ef-a3e7-1b67a4a59178&calc=f66544940b4b2&unp\_tpcid=requestmoney-notifications-requestee&page=main%3Aemail%3ART000186&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.294.0&tenant\_name=&xt=145585%2C150948%2C104038&link\_ref=www.paypal.com\_signin

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [December 3, 2024, 7:15pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/9 "2024-12-03T19:15:13Z")

</div>

Yeah, I get the same kind of links in mine.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 3, 2024, 7:16pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/10 "2024-12-03T19:16:29Z")

</div>

> [@md-2000](#):
>
> A common trick is something like “paypal dot com dot paymentrequirednow dot com”

Nope.

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [December 3, 2024, 7:17pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/11 "2024-12-03T19:17:42Z")

</div>

> [@RitterSport](#):
>
> No, because when I hover over that, I get nonsense at the bottom of the browser, but when I hover over the links in the email, I get [paypal.com](http://paypal.com).

That’s because I had to hack around it rather than use the unicode. I suspect if I did it correctly, it would appear just like paypal. com

How about this: [www.рayрal.com](http://www.xn--ayal-f6dc.com)

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [December 3, 2024, 7:22pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/12 "2024-12-03T19:22:44Z")

</div>

It shows www. xn–ayal-f6dc . com on the bottom of the browser (without the spaces)

---

<div class="post-metadata">

**Author:** ![Joey\_P](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@Joey\_P](https://boards.straightdope.com/u/Joey_P)\
**Post date:** [December 3, 2024, 7:23pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/13 "2024-12-03T19:23:48Z")

</div>

> [@RitterSport](#):
>
> What they probably want you to do is to call the help number…

Or, if the request is real…pay it. It’s not uncommon for scammers to send random invoices to businesses on the off chance someone will pay it without asking questions. At my place, a few times a year, we’ll either get entirely bullshit ‘invoices’ (ie toner) or quasi-bullshit letters\* designed to look like an important bill that needs to be paid soon. In any case, I’ve gotten a few of the paypal things (at my work paypal address) and I just assume it’s this same thing. Send a bill, see if someone pays it.  
When it’s happened to me, it all appeared to come through paypal, if the invoice isn’t there when you sign in, it’s possible TPTB at paypal picked up on the scam and removed the fake invoices.

\*I found these images on the internet, but these are the same letters from the same companys that I get them from. Imagine working accounts payable in a medium sized business and getting this letter. You could track down whomever handles this and ask them, or you could pay it because it’s due soon and you don’t want to lose the domain name. The scammers are hoping for the latter. Yes, it clearly says it’s not a bill, but plenty of people won’t see that and, IMO, it’s designed to deceive.  
[![](https://www.joerussori.com/wp-content/uploads/2021/07/scamletter-scaled-e1625858280501-1024x768.jpg) ](https://www.joerussori.com/wp-content/uploads/2021/07/scamletter-scaled-e1625858280501-1024x768.jpg)

[![](https://150249976.v2.pressablecdn.com/wp-content/uploads/2021/10/scam_letter_domain_name_expiration_notice.jpg) ](https://150249976.v2.pressablecdn.com/wp-content/uploads/2021/10/scam_letter_domain_name_expiration_notice.jpg)

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [December 3, 2024, 7:24pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/14 "2024-12-03T19:24:51Z")

</div>

I think that when I clicked it, PayPal didn’t know about the payment (I wasn’t logged in). Anyway, here’s another request, which again has a call number:

Payment request details  
Amount requested  
$899.99 USD

Note from Mac Store:  
Fraud Alert: Didn’t make this order? Call at 1-810-210-5418

Transaction ID  
U-3JP51877KX955362W

Transaction date  
November 25, 2024

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [December 3, 2024, 7:25pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/15 "2024-12-03T19:25:53Z")

</div>

That’s to get you to call the number.

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [December 3, 2024, 7:27pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/16 "2024-12-03T19:27:53Z")

</div>

That one shows xn–pypal-gra . com on the bottom of the browser. I mean, I was really looking closely, looking at the hover links, etc. My brother took a look. It’s really a paypal link, to the best of my ability as a longtime computer guy.

Yeah, they want you to call the number, that’s it. But the email looks really genuine.

---

<div class="post-metadata">

**Author:** ![DavidNRockies](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidnrockies/32/6279_2.png) [@DavidNRockies](https://boards.straightdope.com/u/DavidNRockies)\
**Post date:** [December 3, 2024, 7:33pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/17 "2024-12-03T19:33:16Z")

</div>

May I refer you to two posts for some possible insight:

> [@Unusually competent phishing attempt (PayPal)](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/48):
>
> The scammer signed up for PayPal business account probably using fraudulent credentials. The person whose credentials they stole will probably never know, they aren’t using the bank account or credit cards to steal money, just to secure the account which gives them access to the invoicing feature of the software. The actual scam happens off-platform. A PayPal business account allows you to send invoices to anyone with an email address through the PayPal server. If you had called the number, the…

> [@Unusually competent phishing attempt (PayPal)](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/49):
>
> Pretty fascinating, @Ann_Hedonia . Good sleuthing ! More on the process (although it doesn’t explicitly say that your invoice email will come from a PayPal [dot] com domain): There does seem to be more info about this one the Web (maybe not ‘more info,’ but some ‘reporting’ that comes to similar conclusions):

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 4, 2024, 4:05pm UTC](https://boards.straightdope.com/t/how-does-this-paypal-payment-request-scam-work/1011126/18 "2024-12-04T16:05:42Z")

</div>

I don’t see any trace of these invoices when I log into my PayPal account. I would think if there were any invoices they would make them straightforward to find. (I am not going to login by clicking a link in the email, even if the URL seems legit.)
