Sunday, May 16, 2004

PayPal 'Phishing' Scam tries to spoof PayPal site

A member of the Band of Gonzos Forum who is also a PayPal Account holder, recieved a suspicious email today. The letter was quite convincing in appearance and detailed that his account was suspected to have been accessed by a third-party. He was not to answer the email, but to log into his account at the PayPal site and follow instructions there.

This was a completely plausible looking piece of mail when I first saw it. But the member pointed out a couple of typos in the letter which raised his eyebrow a little. There was also a link in the mail to the PayPal site, but it was spoofed. Examination of the header proved the mail to not come from the PayPal site at all.

Clicking the link in the mail took you to a site that "appeared" to be PayPal also. But it was actually another site, and this idiot did a shoddy job of trying to cover it up. Still -- the fact is that the letter and the fake site is done well enough that someone may fall for it.

Read the discussion in progress and see the full letter in it's entirety at Band of Gonzos forum.

No comments:

Post a Comment