{"id":6646,"date":"2025-09-04T10:03:35","date_gmt":"2025-09-04T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/04\/threat-actors-attack-paypal-users-in-new-account-profile-set-up-scam\/"},"modified":"2025-09-04T10:03:35","modified_gmt":"2025-09-04T10:03:35","slug":"threat-actors-attack-paypal-users-in-new-account-profile-set-up-scam","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/04\/threat-actors-attack-paypal-users-in-new-account-profile-set-up-scam\/","title":{"rendered":"Threat Actors Attack PayPal Users in New Account Profile Set up Scam"},"content":{"rendered":"<p>    Threat Actors Attack PayPal Users in New Account Profile Set up Scam<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated phishing campaign targeting PayPal\u2019s massive user base has emerged, utilizing deceptive \u201cSet up your account profile\u201d emails to compromise user accounts through an ingenious secondary user addition scheme.<\/p>\n<p>The attack leverages advanced email spoofing techniques and psychological manipulation tactics to bypass traditional security awareness measures, representing a significant evolution in financial <a href=\"https:\/\/cybersecuritynews.com\/hackers-behind-100-million-romance-scams\/\" target=\"_blank\" rel=\"noreferrer noopener\">fraud methodologies<\/a>.<\/p>\n<p>The scam operates through carefully crafted emails that appear to originate from legitimate PayPal addresses such as service@paypal.com and service@paypal.co.uk.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEitrzbHKgiH3x9oSHbk0Oh7pqFK9JdQcso6qDmMw3HPHnn3Z_lwMvdX8KNNw328_i3kwDBs4Ixa0lPgQwvI45s8T-sZQaD1FGG6GTU-ctaoWN4RHcU4BwcgFIBXTjBhzf9Qyl_u7cNgscJqN_6LqL5mDIDFeFYta8Gjvk69NrRQfzKfoizZG0Pr6nyQMkw\/s16000\/Fake%2520email%2520%28Source%2520-%2520Malwarebytes%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake email (Source \u2013 Malwarebytes)<\/figcaption><\/figure>\n<\/div>\n<p>However, threat actors employ address spoofing techniques that exploit inherent weaknesses in email authentication protocols.<\/p>\n<p>The attackers configure their email clients to display fraudulent sender addresses, taking advantage of the fact that most email systems lack stringent verification mechanisms for \u201cFrom\u201d field authenticity.<\/p>\n<p>Recipients receive messages claiming detection of a new payment profile with charges of $910.45 USD at Kraken.com, a legitimate <a href=\"https:\/\/cybersecuritynews.com\/cryptocurrency-trading-platforms-guide\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency trading<\/a> platform.<\/p>\n<p>The emails feature authentic PayPal branding and layout elements, likely extracted from genuine PayPal communications.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEik5a7kiGu96BF9HK8poZlkvzvN3qPG6oJToOMVCVO-x-TabYeC85Jth4862kHVEndZ8ilMnXVSfg7Fcypvf9aFp0wkSx1qgZsFX3mes5jA0ZThMxbXy20leHd7hmVBQI6FWgOqfnj-1MgKIw9a0ddpLpzgaiUiLZ04KyK4R60FQIGaYEECawZEdCXoR7k\/s16000\/Fake%2520email%2520body%2520%28Source%2520-%2520Malwarebytes%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake email body (Source \u2013 Malwarebytes)<\/figcaption><\/figure>\n<\/div>\n<p>Malwarebytes analysts <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2025\/09\/paypal-users-targeted-in-account-profile-scam\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> several critical red flags within these messages, including unusual recipient addresses utilizing compromised domains with \u201c.test-google-a.com\u201d extensions, subject lines misaligned with email content, and absence of personalized greetings that legitimate PayPal communications always include.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-sophisticated-account-takeover-mechanism\">Sophisticated Account Takeover Mechanism<\/h2>\n<p>The campaign\u2019s most insidious element involves redirecting victims to authentic PayPal infrastructure rather than traditional phishing sites.<\/p>\n<p>When users click the embedded links, they unwittingly initiate PayPal\u2019s legitimate secondary user addition process instead of the expected profile setup or payment dispute resolution.<\/p>\n<p>This technique represents a paradigm shift from conventional <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-campaign-attacking-investors\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a> approaches, as it exploits PayPal\u2019s own functionality to achieve malicious objectives.<\/p>\n<p>The secondary user addition process grants extensive account privileges, including payment authorization capabilities.<\/p>\n<p>Once successfully added as a secondary user, threat actors gain sufficient access to drain victims\u2019 PayPal balances and conduct unauthorized transactions.<\/p>\n<p>This approach bypasses many traditional anti-phishing measures since the destination URLs resolve to legitimate PayPal domains, making detection significantly more challenging for both automated security systems and end users.<\/p>\n<p>The campaign has reportedly operated for over a month, targeting PayPal\u2019s 434 million active users through databases of email addresses associated with PayPal accounts or previous PayPal interactions.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attack-paypal-users\/\">Threat Actors Attack PayPal Users in New Account Profile Set up Scam<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attack-paypal-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Attack PayPal Users in New Account Profile Set up Scam A sophisticated phishing campaign targeting PayPal\u2019s massive user base has emerged, utilizing deceptive \u201cSet up your account profile\u201d emails to compromise user accounts through an ingenious secondary user addition scheme. The attack leverages advanced email spoofing techniques and psychological manipulation tactics to bypass [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6646","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6646"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6646"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6646\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}