# Unusually competent phishing attempt (PayPal)

**URL:** <https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [June 1, 2022, 8:21pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519 "2022-06-01T20:21:23Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![bobsmom101](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobsmom101/32/2867_2.png) [@bobsmom101](https://boards.straightdope.com/u/bobsmom101)\
**Post date:** [June 1, 2022, 8:21pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/1 "2022-06-01T20:21:23Z")

</div>

As I’m sure is true of most of you, I get multiple phishing/scam emails per day, most of them laughably crude that end up in the spam folder.

This one was pretty good and made it past gmail’s filter. The return address was “[service@paypal.com](mailto:service@paypal.com)” with no obvious altered characters and the language is colloquial American English. Of course, when I went to my PayPal account (accessed through Chrome, not from the email) there was no such charge on my account.

The giveaways that this is bogus:

It’s addressed to “PayPal User” even though the fine print at the bottom of the message says helpfully: “Emails from PayPal will always contain your full name.” 😅

The message says I’d better do something about this RIGHT AWAY otherwise they will charge me _even though they know it is fraudulent_.

Anyhow, I’m sure no one on this Board would be taken in but if you have less wary friends/relatives you might urge them to increase their vigilance.

[![Imgur](https://i.imgur.com/zLFCr95.gif "imgur.com") ](https://imgur.com/zLFCr95)

---

<div class="post-metadata">

**Author:** ![DavidNRockies](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidnrockies/32/6279_2.png) [@DavidNRockies](https://boards.straightdope.com/u/DavidNRockies)\
**Post date:** [June 1, 2022, 8:27pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/2 "2022-06-01T20:27:24Z")

</div>

> [@bobsmom101](#):
>
> The return address was “[service@paypal.com](mailto:service@paypal.com)” with no obvious altered characters {…}

If you hover over the sender’s name, does it _still_ show a [PayPal.com](http://PayPal.com) email address ?

See step #1:

> **[Tips & Strategies](https://phishing.iu.edu/tips-and-strategies/index.html)**
>
> Learn the basic quick steps to take every time, and expand your knowledge with strategies and tools.

> [@](#):
>
> 1. Recognize
> 
> **Verify the sender is who you think it is.**
> 
> How: Double-click or tap the sender’s name at the top of the email to view the real email address. (In Gmail, hover without clicking.)

---

<div class="post-metadata">

**Author:** ![bobsmom101](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobsmom101/32/2867_2.png) [@bobsmom101](https://boards.straightdope.com/u/bobsmom101)\
**Post date:** [June 1, 2022, 8:33pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/3 "2022-06-01T20:33:05Z")

</div>

_If you hover over the sender’s name, does it still show a [PayPal.com](http://paypal.com/) email address ?_

Yes, it still shows “[service@paypal.com](mailto:service@paypal.com)” If I then click to open the “contact details” window, it still just shows “[service@paypal.com](mailto:service@paypal.com)”

Like I said, these guys are unusually competent.

---

<div class="post-metadata">

**Author:** ![DavidNRockies](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidnrockies/32/6279_2.png) [@DavidNRockies](https://boards.straightdope.com/u/DavidNRockies)\
**Post date:** [June 1, 2022, 8:44pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/4 "2022-06-01T20:44:00Z")

</div>

Wow. I’ve definitely never seen that one before.

You may want to forward that email, along with **[full headers](https://mxtoolbox.com/public/content/emailheaders/)**, to **[phishing@paypal.com](mailto:phishing@paypal.com)**.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [June 1, 2022, 8:46pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/5 "2022-06-01T20:46:57Z")

</div>

“Billing Department of PayPal”

A claim the account was accessed fraudulently yet leaving open that you did make the transaction.  
Telling you to log in for a refund even though the 600.00 hasn’t been charged.  
Since when does a transaction take 24 hours to show up?

The 888 number is not PayPal.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [June 1, 2022, 9:13pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/6 "2022-06-01T21:13:53Z")

</div>

@Mangetout (Atomic Shrimp) breaks down how to recognize phishing emails.

[![](https://img.youtube.com/vi/3gpOM9c6mmA/maxresdefault.jpg "Anatomy of Scam Emails - How To Recognise A Phishing Scam Message") ](https://www.youtube.com/watch?v=3gpOM9c6mmA)

---

<div class="post-metadata">

**Author:** ![3AxisCtrl](https://avatars.discourse-cdn.com/v4/letter/3/ecd19e/32.png) [@3AxisCtrl](https://boards.straightdope.com/u/3AxisCtrl)\
**Post date:** [June 1, 2022, 9:22pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/7 "2022-06-01T21:22:45Z")

</div>

I note several things that seem not quite right:

- “$600.00 USD” should be $US 600.00, or 600.00 USD.
- If an account is known to have been used fraudulently, there’s no need for a phone call.
- No refund is applicable when a bogus transaction is detected & cancelled.
- Parens around service hours are uncalled for.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [June 1, 2022, 10:10pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/8 "2022-06-01T22:10:12Z")

</div>

The writing is a bit weird in places:  
‘Billing Department of PayPal’  
‘Within the automated deduction of the amount this transaction will reflect on PayPal activity’ - is not something PayPal would write.

> [@3AxisCtrl](#):
>
> “$600.00 USD” should be $US 600.00, or 600.00 USD.

Yep. $600 USD = 600 square dollars. Common scammer error.

---

<div class="post-metadata">

**Author:** ![don\_t\_ask](https://avatars.discourse-cdn.com/v4/letter/d/e68b1a/32.png) [@don\_t\_ask](https://boards.straightdope.com/u/don_t_ask)\
**Post date:** [June 2, 2022, 6:58am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/9 "2022-06-02T06:58:53Z")

</div>

> [@Mangetout](#):
>
> ‘Within the automated deduction of the amount this transaction will reflect on PayPal activity’ - is not something PayPal would write.

Or anyone that speaks English.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [June 2, 2022, 7:09am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/10 "2022-06-02T07:09:56Z")

</div>

Certainly not any company that probably has an entire department of people dedicated to the task of corporate messaging

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [June 2, 2022, 7:13am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/11 "2022-06-02T07:13:24Z")

</div>

> [@bobsmom101](#):
>
> The message says I’d better do something about this RIGHT AWAY otherwise they will charge me _even though they know it is fraudulent_ .

This, I think, is the thing that people need to learn to be alert about. Instructions in emails to click a thing _are not to be trusted_, especially if they say they are urgent, or threaten some dire outcome.

Trust should only be granted at the _end_ of a process of rigorous and harsh scrutiny.

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [June 2, 2022, 7:13am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/12 "2022-06-02T07:13:54Z")

</div>

> [@DavidNRockies](#):
>
> > [@bobsmom101](#):
> >
> > The return address was “[service@paypal.com](mailto:service@paypal.com)” with no obvious altered characters {…}
> 
> If you hover over the sender’s name, does it _still_ show a [PayPal.com](http://PayPal.com) email address ?

If you forward the email (but don’t actually send it), is the sender’s email still showing as [service@paypal.com](mailto:service@paypal.com)?

That is one of my standard tests.

---

<div class="post-metadata">

**Author:** ![kambuckta](https://avatars.discourse-cdn.com/v4/letter/k/53a042/32.png) [@kambuckta](https://boards.straightdope.com/u/kambuckta)\
**Post date:** [June 2, 2022, 7:14am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/13 "2022-06-02T07:14:33Z")

</div>

Le sigh. I never get emails like this, nor do I get telemarketers ringing me from Bumfuckistan or elsewhere! I feel so, well, alienated. Am I not worthy of being scammed? Fuck’s sake.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [June 2, 2022, 7:47am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/14 "2022-06-02T07:47:14Z")

</div>

Most large organisations employ DKIM and SPF on their mail servers, which are fairly effective at preventing people from spoofing the ‘from’ address in an email, but the problem with these technologies is that they are optional - so in the case of the PayPal thing:

Your mail server receives a message that claims to originate from paypal . com - the receiving server can check DKIM and SPF, and, based on that information, establish that the message did indeed originate from an official source, however…

If the domain does not have DKIM and SPF set up, there is nothing to check, and your mail server may simply receive the message at face value.

But PayPal definitely has these measures in place, so it not possible to spoof the originating domain - however, what spammers sometimes do is to replace one or more of the characters in the domain name in the From address, with something that looks similar, for example an uppercase i looks like a lower case L; a Cyrillic or Greek letter (equivalent to)R looks like a roman letter P.

If the From address is actually (for example) [service@paypai.com](mailto:service@paypai.com), your mail server will query the DKIM/SPF for ‘paypai’ not ‘paypaL’ - and if that domain doesn’t exist, or has nothing set up, the assumption is that the message is OK.

In a nutshell, the problem is that the security model is ‘trust unless proven false’, because it was added onto a system that still needed to continue working without the security. A better model would have been ‘deny trust until proven true’, but that would break email overnight, until everyone configured their setup.

---

<div class="post-metadata">

**Author:** ![bobsmom101](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobsmom101/32/2867_2.png) [@bobsmom101](https://boards.straightdope.com/u/bobsmom101)\
**Post date:** [June 2, 2022, 11:59am UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/15 "2022-06-02T11:59:22Z")

</div>

Thanks – I reported it as phishing to gmail as well.

---

<div class="post-metadata">

**Author:** ![bobsmom101](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobsmom101/32/2867_2.png) [@bobsmom101](https://boards.straightdope.com/u/bobsmom101)\
**Post date:** [June 2, 2022, 12:02pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/16 "2022-06-02T12:02:22Z")

</div>

Well, while the syntax is odd, it’s as least as coherent as the average post on my local NextDoor.

---

<div class="post-metadata">

**Author:** ![bobsmom101](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobsmom101/32/2867_2.png) [@bobsmom101](https://boards.straightdope.com/u/bobsmom101)\
**Post date:** [June 2, 2022, 12:17pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/17 "2022-06-02T12:17:33Z")

</div>

> [@Bullitt](#):
>
> If you forward the email (but don’t actually send it), is the sender’s email still showing as [service@paypal.com](mailto:service@paypal.com)?

Yes, here’s a snip of the address:  
[![Imgur](https://i.imgur.com/uQhtV42.gif "imgur.com") ](https://imgur.com/uQhtV42)

> [@Mangetout](#):
>
> But PayPal definitely has these measures in place, so it not possible to spoof the originating domain - however, what spammers sometimes do is to replace one or more of the characters in the domain name in the From address, with something that looks similar, for example an uppercase i looks like a lower case L; a Cyrillic or Greek letter (equivalent to)R looks like a roman letter P.

Yeah, I subscribe to your channel (thank you 😉). The “l” (lower case L) might really be an “I” (upper case i) but I don’t know how to tell from looking at the headers.

---

<div class="post-metadata">

**Author:** ![ThelmaLou](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/thelmalou/32/390_2.png) [@ThelmaLou](https://boards.straightdope.com/u/ThelmaLou)\
**Post date:** [June 2, 2022, 12:24pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/18 "2022-06-02T12:24:47Z")

</div>

I’ve gotten quite a few of these. I knew immediately that they were bogus because they come to my junk email address that I NEVER use with PayPal (or indeed with any financial transactions).

I forward them to “[spoof@paypal.com](mailto:spoof@paypal.com).” I suggest others do that, too.

I didn’t read every word of the thread. Apologies if someone else already suggested this.

---

<div class="post-metadata">

**Author:** ![TroutMan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troutman/32/6721_2.png) [@TroutMan](https://boards.straightdope.com/u/TroutMan)\
**Post date:** [June 2, 2022, 4:11pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/19 "2022-06-02T16:11:16Z")

</div>

> [@bobsmom101](#):
>
> The “l” (lower case L) might really be an “I” (upper case i) but I don’t know how to tell from looking at the headers.

Copy it and paste into Word or some other software with tools to convert to upper case.

---

<div class="post-metadata">

**Author:** ![bobsmom101](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobsmom101/32/2867_2.png) [@bobsmom101](https://boards.straightdope.com/u/bobsmom101)\
**Post date:** [June 2, 2022, 6:16pm UTC](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519/20 "2022-06-02T18:16:00Z")

</div>

Duh. Thank you! The characters all convert as authentic (i.e. “l” → “L”)

[Next page](https://boards.straightdope.com/t/unusually-competent-phishing-attempt-paypal/965519.md?page=2)
