Great catch! I would be interested in how scammers keep coming up with these new methods?
How would they even validate their new attack vector? I would like to think that there’s scam A/B testing or something similar…
The whole "put a misleading string in the PayPal name field" thing may be new.
> How would they even validate their new attack vector? I would like to think that there’s scam A/B testing or something similar…
I'm curious about that as well. My guess is that there's nothing as sophisticated as A/B tests with measured results going on, but I'd love to learn more.