Don’t pay that suspicious PayPal invoice — it’s a phishing scam

PayPal logo on a smartphone against a blurred background
(Image credit: Shutterstock)

In order for a phishing campaign to be successful, the cybercriminals behind it first need to ensure that their lures can reach potential victims, which is why they’ve recently turned to PayPal to send out fake invoices.

According to a new report from the Checkpoint-owned cybersecurity firm Avanan, cybercriminals are now using the legitimacy of PayPal to reach the inboxes of unsuspecting users.

Beginning in June of this year, the firm’s security researchers first observed this new technique which utilizes PayPal to send out malicious invoices and request payments. The cybercriminals behind this new campaign use free PayPal accounts to send emails from the company’s domain while spoofing the popular antivirus software brand Norton.

After creating an account, the cybercriminals use PayPal’s features to create fake invoices in which they edit the business name and fake phone numbers to make them appear more legitimate. 

These fake invoices also include a message that reads: “Thank you for purchasing Norton Security Premium plan, if you have not authorized this transaction please call us with your credit card details.” 

Unsuspecting users, who don’t remember signing up for Norton’s antivirus software, may call the number and provide their credit card details to avoid being changed. However, in doing so, they willingly give the attackers their phone number and payment information which can be used in future attacks.

The Static Expressway

This isn’t the first time that Avanan has observed cybercriminals abusing legitimate services in their attacks. In fact, just last month, it released a report detailing how QuickBooks was used to carry out a very similar type of attack.

As both QuickBooks and PayPal are on the Allow Lists of the best email services, emails sent from either service pass right through to reach a user’s inbox. Avanan calls this The Static Expressway and it refers to the practice of cybercriminals utilizing websites that are on static Allow Lists to ensure their phishing emails reach users’ inboxes.

In this case, Avanan notified PayPal of this new attack on July 19 and the company plans on updating its report with additional information once they hear back from the payments giant.

Fish hook on a keyboard

(Image credit: Shutterstock)

How to avoid falling victim to this and other phishing scams

In order to avoid this phishing scam, users first need to monitor their inboxes and PayPal accounts for fake invoices. If you receive an invoice for a product or service you don’t remember purchasing, you should check your PayPal account first to see if you may have ordered something and forgotten about it. However, you should never call the phone number on any fake invoices or provide your credit card details over the phone to anyone.

For those who are curious about the phone number on a fake invoice, Avanan recommends that users look up the phone number in a search engine first. Also, you can check a company’s website to see if the phone number provided on the invoice matches the one listed on their site.

Another big thing to look out for when it comes to phishing emails is a sense of urgency. Cybercriminals and scammers often give potential victims a short time frame to respond to their messages — this is a major red flag in regards to phishing scams and emails.

Now that Avanan is raising awareness to the fact that cybercriminals are abusing legitimate services to send out phishing emails, the companies being impersonated will likely require users to provide even more details when signing up to avoid having their services being misused. 

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A person typing on a computer while hackers use phishing to steal a file from their computer
Phishing: What is it, and how to avoid it
Hooded cybercriminal sitting with laptop surround by hooks
New report details the brands that scammers like to impersonate most — and you'll definitely guess who's at the top
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
A hacker typing on a computer
FBI issues serious warning to iPhone and Android users — stop doing this ASAP
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Latest in Finance Software
Apple Wallet in the App Store on an iPhone
California bringing digital driver's licenses to Apple, Google Wallets
Cash App Taxes logo
Cash App Taxes 2022 review: Simplified free tax experience
FreeTaxUSA logo
FreeTaxUSA 2022 Edition review
TaxAct Deluxe logo
TaxAct Deluxe review: Tax pro help for everyone
TaxSlayer Classic logo
TaxSlayer Classic 2023 (tax year 2022) review
TurboTax logo
Intuit TurboTax Deluxe 2022 review: Tax returns with the best guidance
Latest in News
NFL Sunday Ticket logo for YouTube
NFL Sunday Ticket 2025 pricing revealed — and it's bad news
Diego Luna as Cassian Andor in "Andor" season 2 trailer
New ‘Andor’ season 2 trailer teases more explosive action and a darker edge to the hit ‘Star Wars’ show
Russian flag with padlock smashing through glass
47 VPNs could be axed from Google Play Store following Russian demands
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works