E-mail fraud targets PayPal users - again

Another e-mail scam is doing the rounds, this one attempting to lure PayPal customers to fork over their account details under the pretext of increasing security.

Similar to a previous scam targeting PayPal customers and customers of banks the e-mail uses a deceptively constructed hyperlink in an attempt to trick people into entering their account details on a page that mimics the PayPal style, but does not belong to the company.

The e-mail reads: "Your As part of our continuing commitment to protect your account and to reduce the instance of fraud on our website, we are undertaking a period review of our member accounts." The incorrect grammar used is one hint the e-mail is fraudulent.

Readers are exhorted to click on a link reading "https://www.paypal.com/cgi-bin/webscr?cmd=verification", but which instead takes them to a page with the URL: "http://www.exme.us/~x/". By holding the cursor over the link in the body of the e-mail, the URL it directs to is shown in the display bar at the bottom of the e-mail client.

All the other links on the page point towards legitimate PayPal Web sites.

Advertisement

Talkback 2 comments

  1. This appears to some fraudster trying to discredit eXme.org which is a different site and runs from a different machines as eXme.us. Even though both sites are exactly the same, the fraudster has just made an effort to discredit the eXme.org people. Mark Arena -- 24/06/03

    This appears to some fraudster trying to discredit eXme.org which is a different site and runs from a different machines as eXme.us. Even though both sites are exactly the same, the fraudster has just made an effort to discredit the eXme.org people.

    * Resolved www.exme.org to 80.92.65.10
    * Resolved www.exme.us to 203.22.204.92

    There is a clear difference in domain registerations also:
    Domain Name: EXME.US
    Domain ID: D4366646-US
    Sponsoring Registrar: ENOM, INC.
    Domain Status: ok
    Registrant ID: 7CDB55B23888B816
    Registrant Name: Role Acccount
    Registrant Organization: Globat, LLC.

    Registrant:
    tim (EXME-ORG-DOM)
    carey
    n9170 jordan st
    n9170 jordan st
    appleton, US 54915
    US
    920 733-8254
    920 733-8254
    jurcas@one.lt
    Domain Name: EXME.ORG

    eXme.us appears to be hosted off a machine at Globaldat.com, which is a web hosting company. I've emailed them and by far the best bet in catching this fraudster would be with the cooperation of globaldat.com in finding out where the credit card information is being sent to (most probally an email address) and also from where has the logins into Globatdat's servers come from.

    Regards
    Mark Arena

  2. Although it is not PayPals fault about this scam, it seems their site is not secure enough. I believe they are very slow in dealing with this problem. I advised them that somebody had got hold of my ID and changed it and had purchased goods and credited t Anonymous -- 31/03/05

    Although it is not PayPals fault about this scam, it seems their site is not secure enough. I believe they are very slow in dealing with this problem. I advised them that somebody had got hold of my ID and changed it and had purchased goods and credited them to my paypal account. I advised them of this at the beginning of February but I have not been advised what they had done to recover my US29.95 fraudulently taken out of my credit card. I will not use PayPal again until this matter is cleared up and my account balance is back to NIL.

Add your opinion


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured