Security Alert: New Paypal Phishing Campaign

PayPal being looked at through a glass

Table of Contents

Fortinet’s FortiGuard Labs has identified a sophisticated phishing campaign that exploits Microsoft 365 test domains and distribution lists to bypass traditional email security protocols.  The attackers use free Microsoft 365 test domains and various other mechanisms to send legitimate-looking emails that appear to be from PayPal that lure users into providing their credentials.

The phishing emails closely resemble valid PayPal payment requests, complete with links that appear genuine, and accurate sender details.  Clicking on the link and providing PayPal details grants the attacker access to the users PayPal account, and the ability to perform unauthorised transactions.

This campaign avoids the usual hallmarks of traditional phishing, such as suspicious URLs or poorly written copy, making it much more difficult to identify the email as a scam.

Protecting Yourself

To protect yourself from falling victim phishing scams, be vigilant and suspicious of all email you receive until it’s legitimacy is proven.

The indicators that you should look out for with all of the email you receive are:

  1. Unexpected Emails: Be cautious of unexpected emails, especially those that appear to be from legitimate sources like PayPal. If you’re not expecting a payment request, verify its authenticity before taking any action.
  2. Check the Sender’s Email Address: Even if the email address looks legitimate, check the sender’s email address carefully. Phishing emails often use addresses that are slightly altered or unfamiliar.
  3. Suspicious Links: Hover over any links in the email to see the actual URL. If the URL looks suspicious or doesn’t match the legitimate website, avoid clicking on it.
  4. Urgent or Threatening Language: Phishing emails often use urgent or threatening language to prompt immediate action. Take a moment to verify the email’s legitimacy before responding.
  5. Verify with the Source: If you receive an email that seems suspicious, contact the company or person directly using a known and trusted method (e.g. official website or previously used phone number) to verify the request.
  6. Use Security Tools: We recommend using advanced email security tools that can detect and block phishing attempts, as well as perimiter firewalls that block access to phishing URLs. These tools often use AI and neural networks to analyze user behavior and identify hidden threats that would otherwise go undetected.

Protecting Your Business

  • Use a broad, multi-layered approach:  We recommend implementing a comprehensive cyber-security program to help secure your company and customer data wholistically.
  • Implement ACSCs “Essential 8”: Preparing for and then undergoing an ACSC Essential Eight Assessment will ensure your company’s security baseline will make it much harder for an attacker to compromise your systems or data.
  • Employee Education:  Teaching users how to accurately identify suspicious emails quickly and easily will mitigate the risk of phishing emails significantly.

If you would like more information on this phishing campaign or any other aspect of cyber-security, please feel free to contact our Australian-based cyber-security team.

Windstil provides cyber security consulting for Australian SMBs and SMEs – including Essential Eight compliance audits, ongoing threat management and Virtual CISO support.

Subscribe to our newsletter

  Stay informed with practical IT and cyber security insights, along with company updates, announcements, and the work we’re doing with businesses like yours.