Possible scam

jgustavus
New Community Member

I recently received an e-mail from an entity identifying themselves as "paypal".  They stated that my paypal account had been hi-jacked and that I needed to contact them.  I clicked on the icon www.paypal.com and was sent to a location stating that I needed to give them more information and giving me an access number.  I became suspicious and logged out.  I then logged in to paypal and found no such information about hijacking.  Has anyone else had the same experience.

Login to Me Too
1 ACCEPTED SOLUTION

Accepted Solutions
Solved

PayPal_Jason
PayPal Employee
PayPal Employee

Hi Everyone-

 

Never download something from an email, or at least have your security system run a scan on it even if it's from a trusted source.  You could wind up with viruses, malware or keyloggers on your computer.  This is why PayPal has a Resolution Center within your account if we legitimately need documentation or information from you.

 

A few tips here:

 

1) If you don't know whether an email is from PayPal or not, send it to spoof@paypal.com.  You should get a response back (you may need to check your spam filter if it's aggressive) letting you know if the message was from PayPal or not.

 

2) PayPal will refer to you by the first and last name on the account, not as PayPal Customer or PayPal Account Holder.

 

3) Our Online Safety Essentials area in the PayPal Security Center has some resources for fighting spoof and phishing emails, including a "Red Flags" tutorial and a system that shows a symbol on your email confirming the legitimacy of the message.  You can get to the Security Center from a link in the upper-right hand corner of most PayPal pages.

 

If you have downloaded something from an email or filled out the links, I'd suggest changing your PayPal account password, giving us a heads-up through our Contact Us area (secure email or phone), and running an updated virus / malware scan on your computer. 

 

Thanks,

Jason

View solution in original post

Login to Me Too
26 REPLIES 26

Mogwai
Contributor
Contributor

Yes! I just checked my e-mail and received an e-mail to the same effect. Here is the body of the message:

 

PayPal Resolution Center: Your account is limited.
(Your case ID for this reason is *I omitted the case # myself*)

Dear PayPal account holder,

PayPal is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience This is done for your protection only you, the recipient of this email can take the next step in the remove limitation process

Why is my account access limited?

November 02, 2009:

We have reason to believe that your account was accessed from a different IP address other than the one used at PayPal registration.

Because protecting the security of your account is our primary concern, we have limited access to sensitive PayPal account features. We understand that this may be an inconvenience but please understand that this temporary limitation is for your protection

A verification page will appear after you Log In into your account by clicking the link below

 

Sounds legit, right? Here's the thing: That e-mail address this message was sent to IS NOT THE CURRENT E-MAIL ADDRESS I HAVE ON FILE WITH PAYPAL.I use a different e-mail so if this was legit it should have been delivered to the e-mail I currently use and have on file with PayPal.

This is why after opening the e-mail and reading I visited Paypal and logged in. And I came to the forums here to see if anyone else got a similar e-mail. My advice is DO NOT CLICK any links within the e-mail. These are how these scams work.

Login to Me Too

mike663
Contributor
Contributor

Anyone know if this is legitimate or not? Just wanted to ask before filling it out. Also logged in to my paypal account and cant find anything wrong.

 

Restore your account access

From: PayPal <accounts@cmd-ppl-link.com>

To: undisclosed-recipients:;

Date: Thu, Oct 29, 2009 1:35 pm

Attachment

  

As part of our security measures, we regularly screen activity in the system.
We recently contacted you after noticing an issue on your account.
We requested information from you for the following reason:

- We have observed activity in this account that is unusual or potentially high
risk.

Please download the form attached to this email and open it in a web browser.
Once opened, you will be provided with steps to restore your account access.
We appreciate your understanding as we work to ensure account safety.

Sincerely,


Copyright © 2009 PayPal Inc. Account Review Department.
Login to Me Too

luckydog1
Contributor
Contributor

I really don,t think it is.....

Login to Me Too
Solved

PayPal_Jason
PayPal Employee
PayPal Employee

Hi Everyone-

 

Never download something from an email, or at least have your security system run a scan on it even if it's from a trusted source.  You could wind up with viruses, malware or keyloggers on your computer.  This is why PayPal has a Resolution Center within your account if we legitimately need documentation or information from you.

 

A few tips here:

 

1) If you don't know whether an email is from PayPal or not, send it to spoof@paypal.com.  You should get a response back (you may need to check your spam filter if it's aggressive) letting you know if the message was from PayPal or not.

 

2) PayPal will refer to you by the first and last name on the account, not as PayPal Customer or PayPal Account Holder.

 

3) Our Online Safety Essentials area in the PayPal Security Center has some resources for fighting spoof and phishing emails, including a "Red Flags" tutorial and a system that shows a symbol on your email confirming the legitimacy of the message.  You can get to the Security Center from a link in the upper-right hand corner of most PayPal pages.

 

If you have downloaded something from an email or filled out the links, I'd suggest changing your PayPal account password, giving us a heads-up through our Contact Us area (secure email or phone), and running an updated virus / malware scan on your computer. 

 

Thanks,

Jason

Login to Me Too

donnyguru
Contributor
Contributor

The security center was very helpful.  The main mistake I made was to almost give personal information to a source I came upon through an email link.  I already knew not to do this, but my common sense must have been on holiday Thursday.  The page I was sent to was a great copy of Paypal home, though.  I went back, and every link on there links to legitimate Paypal information, except the sign in button.  The spoof page even had a link in the upper right with a lock and a security link that went to Paypal's security page.  Very wily.

Login to Me Too

Mogwai
Contributor
Contributor

Hi Jason -

 

Thanks for the info. I didn't download anything from the e-mail I received because I immediately found it to be of suspicious origin. I didn't click any links taking me to another page, and I certainly didn't enter any personal info. I just wanted to bring this to attention as well as respond to the original creator of this thread that yes, the e-mail he got was most likely a fake and attempt to steal his info.

 

Login to Me Too

hf
Contributor
Contributor

I have received 2 of these emails recently (in December) and my account _has_ been limited.  However, nothing shows up in the Resolution Center when I log into my account--meanwhile, my business is at a standstill.  This is unacceptable.

 

Additonally, the emails do not contain my full name, only my business name, even though both are listed on my account.

 

And, the emails include a sentence starting with "Case ID Number" yet there is no case number actually included in the email message, nor are their instructions for resolving the issue.

 

The only instruction to correcting the issue is to visit the Resolution Center, yet I have NO cases in the Resolution Center that are open, or are even recent.

 

The email address has the domainkeys verification stamp (look up yahoo email domain keys if you do not know what this is) next to it, confirming that it came from Paypal.

 

When I have attempted to contact Paypal, often the telephone number webpage in Paypal's support center does not function correctely.  When I finally do reach Paypal, often that department is closed and I'm told to call back the next day.

 

I have saved all 30+ emails that I have sent to Paypal in the past on this and similar issues (i.e. constantly being locked out of my account--likely because I use 2 different IP addresses to login to my account showing completely different locations).  And, I have saved all of the very confused replys from Paypal customer service representatives who typically don't appear to read my emails in the first place or perhaps they do not understand English and rely upon computer aided response systems.

 

I am working on moving my business to Google Checkout as much as possible to avoid these issues--this reflects very badly on my business reputation.

 

 

Here is a copy of the message:

 

From: [email address deleted because Paypal would not let me post it in this message]

This sender is DomainKeys verified

 

Hello [deleted for privacy purposes],

As part of our security measures, we regularly screen activity in the PayPal system. During a recent screening, we noticed an issue regarding your account.



We have reason to believe that your account was accessed by a third party. We have limited access to sensitive PayPal account features in case your account has been accessed by an unauthorized third party. We understand that having limited access can be an inconvenience, but protecting your account is our primary concern.

Case ID Number:


For your protection, we have limited access to your account until additional security measures can be completed. We apologize for any inconvenience this may cause.

To review your account and some or all of the information that PayPal used to make its decision to limit your account access, please visit the Resolution Center. If, after reviewing your account information, you seek further clarification regarding your account access, please contact PayPal by visiting the Help Center and clicking "Contact Us".

We thank you for your prompt attention to this matter. Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience.

Sincerely,

PayPal Account Review Department


Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance, log in to your PayPal account and click the Help link in the top right corner of any PayPal page.

PayPal Email ID PP522

Login to Me Too

Squirreleen
New Community Member

Jason, I also received such an email.  Too late, I noticed that the "L" in PayPal" was actually a capital "I", such as in HIJ, rather than L, as in KLM, if that makes any sense.  I also attempted to forward the email to PayPal, but every time I attempted to do so, something weird would happen, and I ended up not being able to do so.  Meanwhile, stupidly I did furnish the credit card on file with PayPal, in answer to the query similar to this:  "please provide your credit card number to verify who you are."  About that time I wised up and left that web site.

Unfortunately, when contacting PayPal, I am no longer sure you are "you," and now believe that this phisher has much too much information about me.  I believe that PayPal is much too vulnerable to such hackers and now respectfully request that my entire account be closed.  I regret that this action is necessary, but for my peace of mind, would you please help me close everything out?

Login to Me Too

ksigma1222
New Community Member

Is this one a scam as well?

 

Hello,

We recently noticed more attempts to log in to your PayPal account from a foreign IP address.

If you accessed your account while traveling, the unusual log in attempts may have been initiated by you.

However, if you are the rightful holder of the account, please visit Paypal as soon as possible to verify your identity:

Then it gave a link to "Activate" my account.  I forwarded it to spoof@paypal.com but plan on doing nothing with it since I logged into paypal separately from this email and saw nothing on my account.

Login to Me Too

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.