UPDATED 20:24 EDT / JULY 21 2022

SECURITY

Phishing scam uses PayPal to send malicious invoices to potential victims

Security researchers have discovered a phishing scam that involves hackers using PayPal Holdings Inc. accounts to send malicious invoices to potential victims.

Detailed today by researchers at Avanan, the scam involves hackers sending malicious invoices from PayPal’s domain, using a free PayPal account they have signed up for. The body of the emails sent spoof brands such as Norton to trick victims into thinking they were legitimate.

Resembling a similar scam that used fake invoices sent from Quickbooks detailed earlier this month, the PayPal invoices include messages such as “thank you for purchasing Norton Security Premium plan, if you have not authorized this transaction, please call us with your credit card details.”

Called a “double spear” attack, the scam makes the users call the number and, when it’s called, the hackers try to make the users pay the invoice, obtaining their credit card details in the process.

The researchers warn that anyone receiving an invoice should Google the number and check accounts to see if there were any charges. In a corporate setting, anyone receiving an invoice is urged to ask the information technology department about of the legitimacy of an email.

“The attack is a reminder of the genius and persistence of threat actors,” Mark Arnold, vice president of advisory services at information security consulting firm Lares LLC, told SiliconANGLE. “They continue to build new tactics on existing ones to profit from security loopholes. Vendors and end users must increase due diligence against new tactics exploiting a combination of trusted applications like email, QuickBooks and PayPal. There are certainly others that attackers are curating to exhaust this tactic before the security loophole is closed.”

Patrick Tiquet, vice president, security and architecture at zero-knowledge cybersecurity software company Keeper Security Inc., noted that this is a very difficult class of phishing attack to counter with the usual technology-based tools.

“Prevention of this kind of attack really comes down to training and awareness,” Tiquet explained. “Users must be made aware that this kind of attack exists and how to recognize it. This is the only way of preventing this, short of filtering and analyzing all emails that appear to be an invoice.”

Image: Avanan

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU