A novel PayPal scam
anderegg.ca
anderegg.ca
I've discovered that if you offer any type of service that allows sending free text messages to other people, it will be abused by spammers or scammers.
For a variation of this problem, I once programmed a sign-up form that sent a confirmation email like "Hello name, please confirm your email...". As soon as spammers found it, they used it to send millions of emails by signing up and putting their spam message in the name field.
It doesn't matter how much info you put in the email around it (like a footer warning about spam). If the email contains any text that can be provided by the attacker, it will be abused.
Paypal should probably not include the seller note in the email, and show the invoice to the user only after asking if they are expecting an invoice.
For this example I'd suggest allowing long names. No one wants to have a computer say "your name is not valid". However, if the goal of personalized email is to be friendly, or some other non-functional reason, consider only including the name in the email if its "short" enough. That seems like a graceful degradation that would limit spam.
Edit: or to address the URL/phone number concern, allow the user to pick that as their name, but not include it in the email.
[1] https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-...
Previous discussion: https://news.ycombinator.com/item?id=32511086
https://krebsonsecurity.com/2022/08/paypal-phishing-scam-use...
I don't really know how you'd prevent this or why anyone would fall for it. It's just sending an invoice. And PayPal clearly says you can safely ignore it if it's not for something you bought.
Sellers need to be able to send invoices, both for online and in-person things (like classes). And they need to be able to send them to any e-mail address, like a student who just signed up.
If you "lock it down", it doesn't work.
A few months ago? I've been getting these intermittently for years.
I don't understand how there can be so much fraud in legacy finance, and everyone simply accepts it without holding the companies responsible for not cracking down harder. Yet if it's on a public blockchain where everyone can observe the movements, it's supposed to be worse? Wonder how much more of it we'd see if bank books were public.
> PayPal Invoicing has no set up or monthly fees. When a customer pays you online, you’re charged a fee based on the amount of the purchase. Fees vary by country or region.
[1]: https://www.paypal.com/us/cshelp/article/how-much-does-it-co...
E.g., factories used to have big signs about "XX Days Since A Time Lost Accident". I've seen more advance factories now posting "XX Days Since A Close Call". Important distinction because studying the close calls and taking action will prevent accidents better than waiting for an actual accident. Same for security failures.
Similarly when I used to own a liquor store and the distributors would come in at the busiest times and say, "Oh, you're busy. Don't worry, I'll check your inventory for you, and you just have to sign off." Sign off, that is, on a huge list of stuff you don't need.
The PayPal invoice form is just a sufficiently scary-looking template to trigger a reaction in someone who might fall for a phone call with the "Coinbase Billing Department". The amount on the invoice is too high for people to accidentally pay but too low to immediately clue the victim in that it's fake.
Don't click on random links and don't call random phone numbers.
It seems that an AI based filter might help? Why not ask the new kid around the block ChatGPT.
> "Dear Customer, You sent a payment of $429.00 USD to Coinbase Corporation. If you did not make this payment or to cancel this transaction, please call our Help Desk number +1 XXX Cancellation after 24 Hours from this email won't be valid for a refund. Have a great day! PayPal Help Desk +1 XXX"
Who is the author of this message
ChatGPT> The author of this message is the PayPal Help Desk.
Maybe it is a bit too easy with the signature in place. Scammers might get smarter so I skipped the signature bit. The response was interesting. > "Dear Customer, You sent a payment of $429.00 USD to Coinbase Corporation. If you did not make this payment or to cancel this transaction, please call our Help Desk number +1 123 Cancellation after 24 Hours from this email won't be valid for a refund. Have a great day!"
who is the author of this message
ChatGPT> The author of this message is likely a representative of a financial institution or payment provider, such as a bank or payment service like PayPal.
On a simpler note, I think it would help PayPal to mention right below the seller note that this message is authored by the seller and NOT PayPal.I'm surprised that it works at all.
> adjective: novel; new or unusual in an interesting way.
People have been scamming companies for a long time with fake invoices, but this is the first time I’ve seen it done at the consumer level.
Through an email server controlled by Paypal, in particular. DMARC is not intended to be some sort of replacement for an email signature. It means something different. This is a good example of that.
This was just a regular anonymous unsigned email...
If the author is referring to that title "seller note to customer" -- I think that is PayPal's standard email template and nothing to do with the scammer.
“Dear Customer, You” is also incorrect. The standard correction would be to add a newline after the comma (which presumably the scammer was unable to do), making it a spacing or perhaps capitalization error. But another valid fix would be to replace the comma with a colon, so you could argue it’s a punctuation error…
Their conclusion was similar: "By sending an email that repels all but the most gullible the scammer gets the most promising marks to self-select, and tilts the true to false positive ratio in his favor."
[1] https://www.microsoft.com/en-us/research/publication/why-do-...
Reported it to their security/phishing inbound.
They couldn’t have chosen a worse scam. The email included Paypal’s anti-phishing footer (including a warning that official emails from PayPal include the customer’s full name) and the invoice was for Bitcoin.
The email was addressed “Dear Customer” and I’d rather douse myself in napalm and run into a bonfire than buy cryptocoins.
A good environmentalist choice! Napalm and flesh produce far less carbon dioxide than a transaction to buy cryptocoins.