PDA

View Full Version : "phishing" with paypal


flowk69
14 September 2006, 09:52
Hello !

I don't know if i'm supposed to post about phishing on this forum but i thought it was interesting for people to be informed about this new one...

Anyway, i received today the following email (that is obviously a phishing) on 3 different emails addresses at the same time...
But what made me think it is a phishing is that i am supposed to have paid a big amount of money to an unknown company. Plus, they start by "dear paypal member" and not by my name and they didn't send it on the email address i gave to paypal but to others where i oftenly receive spams...
And the last thing is that the payment is "unconfirmed" and can be "disputed"!!

So here is the email (and the website they send you on if you click on the paypal logo : http://83.64.121.26/ images/ multishop/. us/cmd_run/PP12refund_clickpotions=_accessaccount/login.htm)


Dear PayPal Member,

This email confirms that you have paid LWPELECTRONICS (sales@lwpelectronics.com) $474.99 USD using PayPal.

This credit card transaction will appear on your bill as "PAYPAL LWPELECTRONICS*".


--------------------------------------------------------------------------------
PayPal Shopping Cart Contents

Item Name: BRAND NEW NOKIA 8800 CELL PHONE
Quantity: 1

Total: $474.99 USD



Cart Subtotal: $454.99 USD
Shipping Charge: $20.00 USD
Cart Total: $474.99 USD



--------------------------------------------------------------------------------
Shipping Information

Shipping Info: Bill Chang
202 N Magnolia Dr.
Saco, ME 04072
United States

Address Status: Unconfirmed

--------------------------------------------------------------------------------
If you haven't authorized this charge, click the link below to cancel the payment and get a full refund.
Dispute Transaction

--------------------------------------------------------------------------------


Thank you for using PayPal!
The PayPal Team
Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the footer of any page.


PayPal Email ID PP120

Slartibartfast
14 September 2006, 11:17
Rule 1) Never click a link on such phishing mails
Rule 2) See rule 1)

The best thing to do with Paypal phishing mails is to "forward as attachment" to spoof@paypal.com they deal with them most efficiently. Same goes for eBay .... send to spoof@ebay.com.

For more discussion go here (http://forum.scambaits.com/showthread.php?p=14250#post14250)

Ernest Rutherford
15 September 2006, 00:52
You are right on, that is defintiely a phishing email.
on 3 different emails addresses at the same time...
The scammers send these emails out to thousands of email addresses at a time, so it stands to reason that you might get a few of the same email in different accounts.

i am supposed to have paid a big amount of money to an unknown company.
That is designed to make you think there has been a mistake that will cost you a lot of money, and get you to click on the link.

Plus, they start by "dear paypal member" and not by my name and they didn't send it on the email address i gave to paypal but to others where i oftenly receive spams...
Those are both telltale signs of phishing. If the email was genuine, it would have gone to the email address you gave PayPal, and wuold have been addressed to your real name.

If you are unsure about an email (and I suggest everyone always be suspicious about strange emails), go to PayPal's real site and check your account from there.

The link in the email belongs to a BASE jumping/aerial stunt company's website, which was probably hacked without their knowledge. Slartibartfast is also absolutely correct that you should never click a link in a phishing email, as phishing sites often contain woms and viruses that can steal information off your computer. I would also advise anyone reading this thread not to click the link in that post for the same reason.

Thank you for posting, and good job spotting the fake.

FW Admin
15 September 2006, 11:30
I've edited the original post to make the link unclickable.