Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 4th, 2009, 15:18 GMT · By

PayPal Classifies Its Own Email as Phishing Attempt

SHARE:

Adjust text size:


PayPal says its own email is a phishing scam
Enlarge picture
In an ironic twist of faith, PayPal security staff mistakenly concluded that a legit email message sent by the company was a phishing attack. The message was forwarded back to them by a security professional who wanted to raise awareness about insecure practices.

Randy Abrams, director of technical education at ESET, the developer of NOD32 antivirus received an email message from PayPal, which contained a link back to an authentication form on the company's website. The security researcher decided to let PayPal know that this practice is exactly the sort of thing phishers abuse and that they should stop doing this.

We don't know if Mr. Abrams actually hoped for PayPal's policy to change due to his commendable effort, but we're pretty sure he wasn't expecting the reply he got. "Thanks for forwarding that suspicious-looking email. You're right – it was a phishing attempt, and we're working on stopping the fraud. By reporting the problem, you've made a difference!" the Paypal security staff responded.

It went on to congratulate the researcher for his diligence and to explain how identity thieves want to steal his personal information through fake emails and websites. It seems that PayPal knows a whole deal about phishing, and it should, since it is one of the most abused brands on the Internet.

According to a report from antivirus vendor Kaspersky Lab released in August, 60% of phishing emails in the first half of 2009 targeted PayPal and eBay users. The report notes that both companies worked hard to educate their customers about such scams, however, continuing to send links to login pages within emails only makes users less vigilant.

"That is why legitimate businesses should NEVER include links to log on pages, or most places. Not even PayPal support can tell the difference between a legitimate PayPal email and a phishing attack," concludes Mr. Abrams. "Again, this is a real, legitimate email from PayPal that I sent to them," he stresses.

TELL US WHAT YOU THINK:

2,805 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Prevx Leads the Fight Against Online Banking Trojans

Rogue PayPal SSL Certificate Available in the Wild

Less Phishing Spam Registered This Year

PayPal Registration Page XSSed

New Phishing Attack Features Live Chat

READER COMMENTS:


Comment #1 by: Red Ink Diary on 06 Dec 2009, 06:30 UTC reply to this comment

This is not news, what Mr Abrams got was an automated bot driven reply. Reports of phishing emails don't get human eyeballs on them. That would require a level of customer service neither eBay nor PayPal are willing to provide.

PayPal is well aware that sending communications with click-able links is poor practice. They have been told over and over, for years. October 30th 2008, eBayInkBlog (http://ebayinkblog.com/2008/10/30/introducing-rich-lamagna-ebay-online-safety-advisor/) had a guest post from Rich LaMagna, the eBay 'security consultant', read through the comments.

Henrietta

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM