Skip Links

New site spoofs PayPal to get billing information

By Paul Roberts, IDG News Service
July 09, 2003 02:42 PM ET
  • Print

A new Web site spoofs the PayPal online payment site and attempts to trick PayPal customers into divulging sensitive account and billing information. The fake Web site is the latest example in what security experts say is a rising trend of "brand spoofing" scams.

PayPal customers are directed to the site, www.paypal-billingnetwork.net, by an e-mail message that appears to come from the Mountain View, Calif., company. The message claims that due to a "recent system flush," the customer's billing and personal information is "temporaly unavailable" (sic).

Customers need to verify their identity by visiting the site or risk having their account canceled, according to the message, which is signed by "Jhon Krepp" from the "PayPal Billing Department."

The actual site is almost identical to PayPal's real site, with the same graphics, layout and wording. In fact, many of the links on the site point back to the actual PayPal Web site. PayPal could not be reached for comment about the scam site.

Adding to the ruse, visitors to the paypal-billingnetwork.net site are greeted with an authentic-sounding pop-up message.

"We've worked hard to help make PayPal even better! However, we have to ask you to re-enter your Billing Information," the message reads, in part. Visitors are asked to have their last PayPal billing statement and credit cards handy before entering the site.

PayPal members who do not enter their billing information will have their PayPal accounts canceled, according to the message.

After acknowledging this message, users are presented with a form that asks for a wide range of personal and financial information including Social Security number, driver's license number, date of birth and credit card information.

Unlike much of the rest of the site, however, the form does not reside on PayPal's Web site, but on a server at a different IP address.

Paypal-billingnetwork.net is registered through Vancouver, Wash., Web hosting company Dotster. Dotster did not immediately respond to requests for comment.

On Tuesday, e-mail filtering company SurfControl PLC of Scotts Valley, California, issued a warning about brand spoofing, saying it has noticed a jump since March in unsolicited e-mail messages tied to fraudulent brand spoofing scams.

Like the most recent PayPal scam, the fraudulent e-mail messages pretend to be from customer service or security officials at well-known companies and direct the spam recipient to phony Web sites that harvest their confidential information, SurfControl said.

Because of its role as an online payments clearinghouse with a large user base, PayPal has long been the target of online criminals.

Recently, however, other high-profile companies have been the targets of brand spoofing, including Best Buy and Discover Financial Services' DiscoverCard.

Sony Electronics., United Parcel Services and Bank of America have also been the targets of brand spoofing in the last few months, SurfControl said.

SurfControl did not receive any brand spoofing e-mail before March, but has received more than five new examples of brand spoofing spam each month since then, the company said. The proliferation of open proxy servers is largely responsible for the problem, SurfControl said.

  • Print

Videos

rssRss Feed