• Home
  • Contact me
  • About
  • Privacy Policy
HiTechBrew.com

Serving up a fresh cup of Tech…

  • Tech
  • News
  • Reviews & Info
  • iPhone
  • Tips
  • iPod
  • Android
Sep
16

Phishing – How to expose a fake PayPal message

How to expose a fake…

In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.

Fake PayPal phishing email is easily mistaken as real.  This is a particularly legitimate looking attack with the purpose of tricking the reader into giving up sensitive account information; specifically PayPal account information.

I’ll give you two easy ways to test if this is legitimate.

  1. Who is it really from?
  2. Check your links… (but DON’T click)

First let’s look at the email message itself – all in all a very real and official looking message.

Fake PayPal Email

Fake PayPal Email

There is nothing blatantly false looking within this message.  Good clear and compelling instructions.  No improper punctuation or misspellings.  Many that originate from another country or from those less versed in the English language are fraught with misspelled words, incomplete sentences and poor punctuation.  We’ll explore the links and or buttons in this message later.

Let’s back up just a little to show the Email as it appeared in the Inbox, you can see it looks quite official.  I’ve highlighted the message so you can easily see the ‘from’ and ‘subject’ information.

Fake PayPal Email Subject

Fake PayPal Email Subject

Next, lets look at who its really from.  Again, I’ve highlighted the information.  At first glance, you see ‘support’.  You might think “Wow”, this is from paypal support.  It may falsely set off an alarm in you of something you need to act upon with urgency!  But wait!  Look at the address a little closer and you will see it states at paypal-media dot com.  That is your first clue that this is  not a legitimate message from PayPal; if it were it more than likely would state at paypal.com.  (Also note that you may need to view or enable full headers to see where your particular email is really from.  Consult your email application help how to view full headers.)

Fake PayPal Email

Fake PayPal Email

Now back to the actual message and the links or buttons.  Again do not click on any of the links or buttons!!! I can’t stress that enough.  All you need to do is move your mouse over the link or button to see where it will take you.  As long as your web browser is displaying the Status Bar, you will see what is behind these links or buttons.  Resting my mouse over the “Confirm” button reveals a web address clearly not PayPal as well as a very long crypictic address.  Another danger clue that this is fake.  I’ve highlighted the address in the status bar below.  Again, simply moving the mouse so it rests over the button will show you the information.  Don’t click it!!!

Fake PayPal URL

Fake PayPal URL

This message is without a doubt a Phishing attempt to steal your account information!

The final steps are to forward the message to spoof@paypal.com and delete the email message from your inbox.  As you can see in this picture, PayPal instructs us to forward then delete the message.  Their support staff can then act upon the sender as well as probable fake websites used in collecting or stealing your account information.

Forward suspicious email to PayPal

Forward suspicious email to PayPal

Stay safe.  Be diligent.  And don’t fall prey to these thieves.

How has this helped you?  Or what further information would you like to see?

Let me know in the comments below.

  • Share this:
  • Reddit
  • Facebook
  • Digg
  • StumbleUpon

Tags: Browser Security, Computer Security, Fake PayPal Email, Fraud, Internet Security, PayPal, Phishing, Stealing Account Information

Posted by David Tech Subscribe to RSS feed

2 Comments to “Phishing – How to expose a fake PayPal message”

  1. Polprav says:
    October 16, 2009 at 7:58 pm

    Hello from Russia!
    Can I quote a post in your blog with the link to you?

    Reply
    • David says:
      October 18, 2009 at 10:06 pm

      Hello! Thank you for asking. That should be okay, thank you.

      Reply

Leave a Reply

Click here to cancel reply.

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Recent Posts

  • Techie Takes On Tomatoes
  • Slice of Raspberry Pi
  • Create a Wi-Fi Hotspot Anywhere
  • PointHub Reveals Thousands of “Free” Rewards Airline Flights Still Available for Thanksgiving Travel
  • Environmentally Friendly Energy-storage membrane

Archives

  • May 2012
  • February 2012
  • November 2011
  • October 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • April 2011
  • January 2011
  • November 2010
  • October 2010
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
RSS

Twitter Twitter
grab this
Copyright © 2012 HiTechBrew.com All rights reserved. Amazing Grace/grace_theme/amazinggrace theme by Vladimir Prelovac.