PhishTrackers.com

Report Phishing Scams Easily & Anonymously


Account Issues! (Kwai Chung, Hong Kong)

Report# A215

Reported on: Friday, 25 January, 2008  19:49
Updated On: Wednesday, 29 February, 2012  16:00
Reply to: (Use contact form below)
Date Reported 25th February 2005
Apparent Sender PayPal

Return Address < service@paypal.com >


Subject Account Issues!
Format HTML
Method Spoof email links to a spoof webpage where victim is prompted to enter their details believing the site is genuine. Details are then forwarded to a local script and captured.


Bogus Web Content? Yes
URL of web content http://202.181.165.238/wamu/paypal/


RISK LEVEL MEDIUM
WARNINGS 1. Email claims to be from PayPal asking you to confirm your account data by clicking on the link. You will be taken to a spoof login page where your details will be captured by the phishers.

2. PayPal never send users emails requesting details in this way.

3. URL of spoof website disguised as "https://www.paypal.com/cgi-bin/webscr?cmd=login-run/". This looks secure (https), but is NOT!

4. Real URL looks nothing like PayPal!

5. Website traced to Kwai Chung, Hong Kong.






" Due to recent activity, including possible unauthorised transactions placed on your account, we have temporarily suspended activity on your account in order to allow us to investigate this matter further."

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.



The Spoof Email ...




Dear PayPal valued member,

Due to recent activity, including possible unauthorised transactions placed on your
account, we have temporarily suspended activity on your account in order to
allow us to investigate this matter further. If you believe that this action may
have been taken in error, or, if you feel that your account may have been
tampered with, please respond to this message so that we can provide additional
information and work with you to resolve this issue.

After responding to the message, we ask that you allow at least 72 hours for the
case to be investigated. Emailing us before that time will result in delays. We
apologise in advance for any inconvenience this may cause you and we would like
to thank you for your cooperation as we review this matter.
However, failure to update your records will result in account suspension.

Once you have updated your account records your PayPal will not be
interrupted and will continue as normal.

Please follow the link below
and renew your account information.
https://www.paypal.com/cgi-bin/webscr?cmd=login-run/

If you have received this notice and you are not the authorised account holder,
please be aware that it is a violation of PayPal policy to represent oneself as
another PayPal user. Such action may also be in violation of local, national,
and/or international law. PayPal is committed to assist law enforcement with any
inquires related to attempts to misappropriate personal information with the
intent to commit fraud or theft. Information will be provided at the request of
law enforcement agencies to ensure that perpetrators are prosecuted to the
fullest extent of the law.

Best Wishes,


PayPal Service Department
PayPal Trust and Safety





The Spoof Website ...

Spoof website not online at time of report...