Ask HN: PayPal allows to issue invoices allowing for near perfect phishing. Why?
imgur.com
imgur.com
The invoice comes with a "Note from Zachary Bos: purchase of Binance Coin (BNB) $ 789. 97 was approved. If you have not done this and need the Refund, Call us immediately at + 1 (877) 462-0959"
The e-mail is legitimate, so I logged into PayPal and I see that the invoice is actually so well formatted that it manages to inject that fake contact number almost perfectly (see the screenshot attached). Nothing else makes sense, but I can imagine many will actually call this number under impression that it is a legitimate PayPal number. I actually called them, got a long-distance DTMF signal for a few secs, someone with South-Asian accent responded, I hung up immediately. They called from another number, same person, pretending they were PayPal. I immediately jumped into the "no you're not, you m***cker" rhetorics, and they responded back in their own language, presumably with their own slurs.
How is it possible that a company this big can let something like this slip through? Allowing users to format the invoice and add a fake contact number must be to the anti-phishing team what allowing SQL injection is to the backend team?
EDIT: I also realized that this is a UI failure, as the note is prepended with an ambiguous "Note to customer:", instead of e.g. "Note from the invoice issuer:"
Two cases:
1) you logged into your Paypal account and the payment is registered there
2) you logged into your Paypal account and the payment is NOT registered there
If #1 you actually made the payment or someone accessed your Paypal account and made it (your account has been hacked), you need to contact Paypal through their site or official telephone number to ask for chargeback.
If #2 you have been targeted by a phishing attempt, there was no payment of $789.97, so you have nothing to be refunded of.
From what you posted, it seems much more likely to be #2, but I cannot understand your reference to "injecting" the fake contact number, in this case the whole invoice (and e-mail message) is fake.
No payment was made. They just sent an "invoice estimate" at my email, presumably randomly. No hacking was done, this is a phishing attempt, not a hacking attempt. This is why they so "wholesomely" offer that phone number to contact them if anything went wrong and I needed a "Refund". That's how they legitimize that phone number and increase their chances of a successful attack.