New PayPal Phishing Scam Exploits MS365 Tools and Genuine-Looking Emails

Share:

Fortinet uncovers a new PayPal phishing scam exploiting legitimate platform features. Learn how this sophisticated attack works and how to protect yourself from falling victim.

  • Phishing Scam Targets PayPal: Scammers exploit PayPal’s system to link victim accounts to unauthorized addresses.
  • Legitimate-Looking Emails: The scam uses real-looking emails and valid PayPal login pages to deceive users.
  • Microsoft365 Exploit: Attackers use MS365 domains to send PayPal money requests, bypassing phishing filters.
  • Account Takeover: Victims unknowingly link their PayPal accounts to the scammer, risking financial loss.
  • Stay Safe: Avoid unsolicited emails, verify URLs, and enable 2FA to protect your PayPal account.

Fortinet’s FortiGuard Labs has identified a sophisticated PayPal phishing scam targeting unsuspecting users by exploiting a loophole in the platform’s system. According to Fortinet’s CISO (Chief Information Security Officer) Carl Windsor, the scam leverages legitimate PayPal functionality to trick users into linking their accounts to unauthorized addresses, potentially granting attackers control over their finances.

The attack utilizes a seemingly legitimate email, often with a valid sender address and a genuine-looking URL. However, the true danger lies within the email’s content. It directs recipients to a legitimate PayPal login page, prompting them to log in to investigate a supposed payment request.

Screenshot of the actual phishing email (Via Fortinet’s FortiGuard Labs)

Further probing revealed that the scammer registered an MS365 test domain and created a Distribution List containing victim emails (Billingdepartments1gkjyryfjy876.onmicrosoft.com), then sent a legitimate PayPal money request to all recipients.

They added the list to the PayPal web portal and distributed it to targeted victims. The Microsoft365 SRS rewrite scheme rewrites the sender to pass the SPF/DKIM/DMARC check. It is worth noting that Microsoft365 SRS (Sender Rewriting Scheme) is a feature in Microsoft 365 that rewrites the sender address of an email message.

Once the victim logs in, the scammer’s account is linked to the victim’s account, allowing them to take control of the victim’s PayPal account, a trick that bypasses PayPal’s phishing check instructions.

“The beauty of this attack is that it doesn’t use traditional phishing methods. The email, the URLs, and everything else are perfectly valid. Instead, the best solution is the Human Firewall—someone who has been trained to be aware and cautious of any unsolicited email, regardless of how genuine it may look,” Windsor wrote in a blog post.

This new phishing scam highlights the importance of cybersecurity awareness. Users must be cautious of unsolicited emails, avoid clicking on links or attachments from unknown senders, hover over links to verify URLs, and never enter login credentials on websites unless certain of the authenticity. Enabling two-factor authentication (2FA) on PayPal accounts can further enhance security.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:55 pm, Jan 14, 2025
weather icon 9°C
L: 8° | H: 10°
overcast clouds
Humidity: 91 %
Pressure: 1034 mb
Wind: 6 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 8:00 am
Sunset: 4:18 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
8° | 10°°C 0 mm 0% 4 mph 91 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 9°°C 0 mm 0% 3 mph 97 % 1035 mb 0 mm/h
Thu Jan 16 9:00 pm
weather icon
5° | 9°°C 0 mm 0% 4 mph 96 % 1034 mb 0 mm/h
Fri Jan 17 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 5 mph 92 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 3 mph 90 % 1033 mb 0 mm/h
Today 9:00 pm
weather icon
7° | 9°°C 0 mm 0% 4 mph 91 % 1034 mb 0 mm/h
Tomorrow 12:00 am
weather icon
8° | 9°°C 0 mm 0% 3 mph 93 % 1034 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 8°°C 0 mm 0% 3 mph 95 % 1033 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 2 mph 96 % 1034 mb 0 mm/h
Tomorrow 9:00 am
weather icon
7° | 7°°C 0 mm 0% 3 mph 97 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 2 mph 89 % 1034 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
9° | 9°°C 0 mm 0% 2 mph 89 % 1033 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
7° | 7°°C 0 mm 0% 2 mph 95 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€94,082.56
3.46%
Ethereum(ETH)
€3,133.41
4.64%
XRP(XRP)
€2.59
6.44%
Tether(USDT)
€0.97
0.01%
Solana(SOL)
€181.79
3.05%
Dogecoin(DOGE)
€0.345731
7.22%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000020
3.83%
Pepe(PEPE)
€0.000017
5.34%
Peanut the Squirrel(PNUT)
€0.60
14.93%
Scroll to Top