The latest PayPal phishing expedition…
——
From: service@paypal.com
Subject: Your Paypal Account

Dear PayPal user,
Your account has been flagged in our system as a part of our routine security measures. This is a must to ensure that only you have access and use of your paypal account and to ensure a safe PayPal experience. We require all flagged accounts to verify their information on file with us. To verify your information, please click here.

Thank you for using PayPal!
——
Before you respond…

If you’re using Outlook, right click and View Source. Note that logos and gifs really link to www.paypal.com. However, under “please click here” lurks www1-paypal.com. A whois check from our tool site reveals the www1-paypal.com registrant and admin as Virginia Treworgy of Manomet, Massachusetts. The same check of paypal.com returns the registrant as PayPal Inc. of San Jose, CA, with ebay as admin.

More Clues. PayPal says:

  • “Emails from PayPal will address you by your first and last name or the business name associated with your PayPal account. Fraudulent emails often include the salutation Dear PayPal User or Dear PayPal Member, and;
  • To safely and securely access the PayPal website or your PayPal account, open a new web browser (e.g., Internet Explorer or Netscape) and type in the following: https://www.paypal.com/”

Wondering what kind of registrar would take the order? Take it up with GoDaddy Software.

Meanwhile, we’ve set our spam appliance to junk messages containing “www1-paypal.com”.

More…
Microsoft Phisher-Hook Hits Snag
Bank Scams Sweep Net