Unsuspecting users are lured to a cleverly designed PayPal replica

Apr 5, 2013 08:00 GMT  ·  By

PayPal customers are advised to be on the lookout for bogus emails entitled “Please update your billing information.”

The fake notifications, apparently originating from “[email protected],” read something like this:

“Following an audit of your account, we must advise that your account has been limited. It has come to our attention that your PayPal Billing Information records are out of date.

That requires you to update the Billing Information If you could please take 5-10 minutes out of your online experience and update your billing records, you will not run into any future problems with PayPal's online service.

However, failure to update your records will result in account termination. Once you have updated your account records, your PayPal session will not be interrupted and will continue as normal. Failure to update will result in cancellation of service, Terms of Service (TOS) violations or future billing problems.”

PayPal customers will probably notice that the emails don’t look like the legitimate ones sent by the payment processor. However, since they don’t contain any major spelling or grammar mistakes, some users might be tricked into thinking they’re genuine.

While the notification itself isn’t very well designed, the website that hides behind the link is.

Users who enter their details on the fake PayPal login page will actually hand them over to the attackers.

Currently, most browsers and antivirus solutions flag the website as being malicious. However, the cybercriminals that run the scheme might move it to another domain, if they haven’t done so already.

PayPal customers are advised to be on the lookout for such emails. If you’re a victim, change your PayPal password immediately.

If you utilize the same password for multiple accounts, make sure you change all of them.

Photo Gallery (2 Images)

Bogus PayPal notification
Fake PayPal login page
Open gallery