New PayPal phishing campaign is stealing credit card info — what you need to know

PayPal logo on a smartphone against a blurred background
(Image credit: Shutterstock)

The cybercriminals behind a new phishing campaign are impersonating PayPal by sending out fake order confirmations in an attempt to steal credit card information from unsuspecting users.

Back in November of last year, security researchers from the Check Point-owned email security firm Avanan spotted a similar campaign that spoofed Amazon. These attacks were successful because they used legitimate Amazon links and forced users to make a phone call to cancel their fake orders.

Now Avanan has discovered a similar phishing campaign that impersonates PayPal but once again has users call the attackers themselves in an attempt to cancel a cryptocurrency order placed on the payments platform. However, instead of cancelling the fake order, phone numbers are harvested for future attacks and a user’s banking information can also be stolen as well.

If you’ve received any suspicious emails from PayPal recently, this is what you need to know to avoid falling victim to this scam.

Using fake PayPal order confirmation emails as a lure

Woman talking on the phone looking at a laptop

(Image credit: René Ranisch/Unsplash)

In this new phishing campaign, the attackers first send out what looks like a PayPal order confirmation informing potential victims that they purchased over $500 worth of Dogecoin. If they want to cancel the order, a customer support number is provided at the bottom of the email.

While calling the number may seem like the right thing to do, it actually isn’t as the cybercriminals behind this scheme can use your phone number to carry out other cyberattacks through text messages, calls or WhatsApp messages. As Avanan’s researchers point out in a blog post: “Just one successful attack can lead to dozens of other ones."

Although the number listed on the emails seen by the researchers is from Hawaii, those behind this campaign and others like it are typically not based out of places like Hawaii and instead register a phone number to a US-based area code before forwarding calls to an international relay.

The reason this attack works is because there aren’t any links in the body of the email sent out to users. As a result, the message is able to bypass email security filters and end up in the inboxes of potential victims.

How to avoid falling victim to this scam and others like it

In order to avoid this new PayPal phishing campaign, Avanan recommends that users first look at the sender’s email address to make sure it’s legitimate. From here, they should check their PayPal account where they’ll see that the order in question is not in their account. This is easy to do as the cybercriminals provide a transaction ID and date which won’t appear in your PayPal order history.

It’s also worth noting that cybercriminals frequently impersonate major online retailers like Amazon and payment services like PayPal. If you have a legitimate email from one of these companies saved in your inbox, it’s easy to compare the two to see if they have similar addresses, formatting, etc. At the same time, you should always be on the lookout for spelling and grammatical errors as these are a big red flag and often make it easy to spot phishing emails.

Finally, you should always exercise caution when calling a number from an email. If you do decide to call, never provide your banking and payment information over the phone as no legitimate company would ever ask you to do so.

Next: Don’t fall for these holiday scams — get your last minute shopping done safely.

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A person typing on a computer while hackers use phishing to steal a file from their computer
Phishing: What is it, and how to avoid it
A hacker typing on a computer
FBI issues serious warning to iPhone and Android users — stop doing this ASAP
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
iPhone 15 Pro Max shown in hand
iMessage under attack from scammers sending phishing messages — don’t fall for it
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now
WWDC logo on yellow background
Apple WWDC 2025 date set for June 9 — iOS 19, Apple Intelligence and more expected
Motorola Razr Plus 2024 cover display
Motorola Razr Plus (2025) leaked specs hint at bigger upgrades — here's what we know