Wednesday 7 May 2008

PayPal | Remove limitations

It's been a quiet few days - nothing to post here for a while. Then this email arrived aimed at PayPal and seconds later a genuine PayPal email about anti-phishing.

The email looks genuine enough and as it was received with a genuine security email, did make me wonder, for a half second. Then I saw the "click on the following link" and knew straight away it was fake (Ebay would not include such a link). Then a quick glance at the To: field (undisclosed-recipients) and there's no doubt that it's phishing - Ebay would only email me if there was an account problem and would mention my name in the email.

Lastly, the email claims that something happened on February 15th - that's ages ago. Why would PayPal take almost 11 weeks to respond?

The link claims to go to https://www.paypal.com/cgi-bin/webscr?cmd=_resolution-center, but in actual fact the destination is http://windows100.neodigit.com/online.paypal.com/www.paypal.com/us/webscr.html?cmd=_login-run. I can't find anything about the site, but it looks dangerous. Don't touch the link.

Here's the email content:

PayPal is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience.

Why is my account access limited?

Your account access has been limited for the following reason(s):

Feb 15, 2008: We have reason to believe that your account was accessed by a third party. Because protecting the security of your account is our primary concern, we have limited access to sensitive PayPal account features. We understand that this may be an inconvenience but please understand that this temporary limitation is for your protection.

(Your case ID for this reason is PP-257-057-154.)


To remove the limitation click on the following link:


https://www.paypal.com/cgi-bin/webscr?cmd=_resolution-center


Regards,
PayPal Security Departament

No comments: