Beware: PayPal "New Address" Feature Exploited for Phishing Scams

Cybercriminals are abusing PayPal’s address settings to send scam emails that look like official notifications. These emails claim a new shipping address has been added to your PayPal account and include a fake purchase confirmation for a MacBook M4. The goal is to trick users into calling a fake PayPal support number, where scammers try to gain remote access to their devices.
- Legitimate-Looking Emails – Scammers exploit PayPal’s system to send emails directly from "service@paypal.com," making them appear genuine.
- Fake Purchase Notification – Victims receive emails stating that their address has been changed and a MacBook M4 has been purchased using their account.
- Scammer’s Fake Support Number – The email urges recipients to call a given number if they did not authorize the purchase.
- Remote Access Trick – Calling the number leads to scammers who try to convince users to install remote access software, allowing them to steal data and money.
- Exploiting PayPal's Address System – Scammers insert fake messages into the "Address 2" field, which gets included in PayPal’s confirmation email.
- Forwarding Scam Emails – The scam emails are sent to a mailing list, allowing cybercriminals to target multiple victims at once.
This scam is highly deceptive as the emails come directly from PayPal’s official address, bypassing spam filters. If you receive such an email, do not call the number or install any software. Instead, log in to your PayPal account directly and verify if any changes were made. Stay cautious, and never share sensitive information over the phone.
Comment(s)
Categories
- Other (42)
- Ransomware (135)
- Events and News (27)
- Features (45)
- Security (452)
- Tips (79)
- Google (23)
- Achievements (10)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (43)
- Malware Alerts (199)
- Cyber Attack (242)
- Data Backup (11)
- Data Breach (90)
- Phishing (151)
- Securty Tips (1)
- Browser Hijack (17)
- Adware (15)
- Email And Password (67)
- Android Security (61)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (7)
- vulnerability (56)
- Hacker (31)
- Spyware (9)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (4)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (10)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (8)
- Impersonation phishing (1)
- DDoS (5)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)
Recent Posts
Archive
Tags
cyber attack
phishing
data breach
ransomware
cyber threats
ransomeware
phishing attacks
android malware
malware
financial security
data theft
phishing attack
cyber security
cybercrime
network security
data stealing
phishing scam
lockbit
data protection
twitter
data security
critical vulnerability
cyber fraud
cyber threat
trojan
cert-in
financial fraud
phishing email
microsoft
cybercriminals
ddos
india
ddos attack
cyber attack in india
play store
winrar
pakistan-backed hacker
email phishing
clop
server security
android
malicious apps
clop gang
android apps
cryptojacking
ransomware attack
cyberthreats
ransomware attacks
december cyber attacks
databreach