02/14/2020
New PayPal Phishing Email Scam Wants Your Social Security Number [Source - www.tripwire.com]
Tripwire, 11 Feb 2020: Security researchers have spotted a new PayPal phishing email scam that tries to steal a victim’s Social Security Number (SSN), among other sensitive data. The attack email informed a victim that their PayPal account was locked, and it instructed them to click a “Secure and update my account now !” button. Doing so directed a user to a bit.ly link pointing to a redirection mechanism, which sent them to a phishing website. The first page on the site asked the user to provide their PayPal credentials. After receiving those details, the scam instructed them to confirm their billing details including their address and phone number. Next, it moved on to requesting a user’s payment card details. It’s at that point when the campaign went for broke and attempted to gain as much as possible from the user. It did this by asking that the user provide their birth date, Social Security Number and card PIN. News of this scam follows less than two months after researchers spotted a PayPal ruse using a valid SSL certificate to steal a victim’s bank account credentials, payment card details and email login data.