I just got a scam email from someone trying to hijack your personal information using PayPal as decoy.
The scammers will try to give you the impression that your PayPal account has been limited and you need to provide them with some additional information to prove you are actually you. This email wasn't sent to my real PayPal email address and that was the thing that got me digging deeper into this. The scary thing is that they had already my full name and my address.
Dear [my full name] ,
PayPal Resolution Center: Your account is limited.
Why is my account access limited?
As part of our security measures, we regularly screen activity in the PayPal system. During a recent screening, we noticed an issue
regarding your account:
Our system detected unusual number of invalid logging attempts on your account from these blacklist ip address.
(Your case ID for this reason is PP-XXXXXXX)
How can I restore my account access?
For your protection, we have temporary suspended access to your account until additional security measures can be completed. We apologize for any inconvenience this may cause. In order to assist us with this security measure, we ask that you send us a photocopy or scan of one document from each of the three categories listed below and return them via email to security@paypalcompany.com :
- A clear copy of your Passport, Photographic Drivers License or I.D. Card (both sides).
- A clear copy of both sides of the credit/debit card on your paypal profile.
- A clear copy of a recent bank statement or utility bill on which your name and address ( [my correct address]
) are clearly visible and less than 3 months old.
Completing all of the checklist items we will manually restore your account access.
Thank you for using PayPal!
The PayPal Security Department
——————————
——-
Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance, log in to your PayPal account and click the Help link located in the top right corner of any PayPal page.
PayPal Email ID PP-XXXXXXX.
The domain used in this scam (paypalcompany.com) sounds like a real PayPal site, but don't be fooled by just the
domain name. This site is hosted in Holland and fromwhat I know PayPal don't got any servers there. The
whois recoreds indicate that the domain belong toPayPal Inc, but the name servers aren't the usual for PayPal web sites:
ppns1.den.paypal.com
ppns2.den.paypal.com
ppns2.phx.paypal.com
ppns1.phx.paypal.com
Luckily the domain has already been blocked in Firefox as a fake web site so you can't access it by accident. But I guess you still can send away the documents by email, and if you ahve already done so you should visit the real PayPal web site and change your passwords. If you need help selecting a random password you can check out the
Password Generator at XavierMedia.com.
So the lesson learned in this case is that you always have to do some background checks before you send away any documents.