NEWS Russian hackers are suspected of being behind a professional-looking but fake PayPal email scam designed to steal a person's financial and personal details for identity theft. The email, which has being doing the rounds this week, is a much more detailed and convincing version of the long-running email that asks users to confirm their PayPal account details. One silicon.com reader, Sarah Waller, who received the email, was concerned enough to try and contact PayPal directly. She said: "If this is not genuine then how have this company established that I have a Paypal account? Personally, I find it peculiar that PayPal are asking for such highly sensitive information to be sent without requesting that customers log into a secure server, particularly that they are asking for ATM Pin number along with credit card number, password and email address." The fake message appears to come from the billing department at PayPal.com and asks people to click on a link taking them to a genuine-looking PayPal page and re-enter their account details. Once there the victim is presented with a convincing version of the PayPal site with a list of fields including name, address and date of birth, social security number, driving licence number, mother's maiden name, credit card and bank account details and PIN numbers, email address and password. In short, that's just about all the information anyone would need to commit complete identity theft and use the details to apply for credit cards and loans. The fake site also has links to a genuine PayPal 'help' section and corporate information and press releases from the real site. Security experts believe PayPal will be able to shut the site down almost immediately for breaching its trademark but said the perpetrators will simply find another hosting company and start again. Chris McNab, technical director of security consultancy Matta, told silicon.com: "This comes down to the hosting companies being lax when setting up the account. They have to tackle this problem when setting up sites." Although the account with the web hosting company will probably have been set up using stolen credit cards and proxy addresses, McNab said the most likely culprits are Russian hackers who could be tracked down. "Law enforcement need to monitor traffic to and from the server. If the FBI or local law enforcement could put logging and auditing on the systems and gather IP addresses of the Russian hackers when they come in to download the details they could track them." PayPal was contacted but no-one was available for comment.
Russian hackers behind fake PayPal email scam?
Convincing but fraudulent website tries to get users to enter credit card and bank account details...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





Comments
There are 4 comments. Join the discussion
1. anonymous
The most interesting hoax/scam was the one involving a 'US IMMIGRATION US lottery' winning to our family, (that was in summer 2002) whereby we were informed that we won the US American Nationality lottery and they proceeded to ask us about our family details, bank details, etc.. and a request for payment of $49 as a deposit to have the papers processed, with a New York correspondence address. Unfortunately, we nearly fell for the trap, nearly believed this hoax, but in the end it dawned on us that they are up to swindling us of our account, the moment they started asking for our bank details, credit card and payment of $49, this stopped us in our tracks....
2. Josh
... Almost fell for it too. Decided to log into my PayPal account and it wasn't limited. That could have really sucked...
3. sarah
I had a similar experience i had an email saying that there were attempts to hack my account can i confirm my details luckily an ebay spoof had also just been sorted for me i did not use the links i just went directly to the site from a new page and informed paypal
4. anonymous
I had these mail messages as well. In the end I emailed PayPal. They are genuinely asking on their site for debit account details to prove your status which has created an opportunity for scammers
I said my credit card was protected against fraud but not access to my bank account & there was no way I could tell whether a service message was genuine or not. Unlike my Bank, they didn't seem to support a secure message service from within a logged on session to their site.
I removed my card details and de-registered. I now know that all further emails from PayPal are scams and can filter them out as spam!