Skip Links

Network World

  • Social Web 
  • Email 
  • Close

New site spoofs PayPal to get billing information

By Paul Roberts , IDG News Service , 07/09/2003
  • Share/Email
  • Comment
  • Print

A new Web site spoofs the PayPal online payment site and attempts to trick PayPal customers into divulging sensitive account and billing information. The fake Web site is the latest example in what security experts say is a rising trend of "brand spoofing" scams.

PayPal customers are directed to the site, www.paypal-billingnetwork.net, by an e-mail message that appears to come from the Mountain View, Calif., company. The message claims that due to a "recent system flush," the customer's billing and personal information is "temporaly unavailable" (sic).

Customers need to verify their identity by visiting the site or risk having their account canceled, according to the message, which is signed by "Jhon Krepp" from the "PayPal Billing Department."

The actual site is almost identical to PayPal's real site, with the same graphics, layout and wording. In fact, many of the links on the site point back to the actual PayPal Web site. PayPal could not be reached for comment about the scam site.

Adding to the ruse, visitors to the paypal-billingnetwork.net site are greeted with an authentic-sounding pop-up message.

"We've worked hard to help make PayPal even better! However, we have to ask you to re-enter your Billing Information," the message reads, in part. Visitors are asked to have their last PayPal billing statement and credit cards handy before entering the site.

PayPal members who do not enter their billing information will have their PayPal accounts canceled, according to the message.

After acknowledging this message, users are presented with a form that asks for a wide range of personal and financial information including Social Security number, driver's license number, date of birth and credit card information.

Unlike much of the rest of the site, however, the form does not reside on PayPal's Web site, but on a server at a different IP address.

Paypal-billingnetwork.net is registered through Vancouver, Wash., Web hosting company Dotster. Dotster did not immediately respond to requests for comment.

On Tuesday, e-mail filtering company SurfControl PLC of Scotts Valley, California, issued a warning about brand spoofing, saying it has noticed a jump since March in unsolicited e-mail messages tied to fraudulent brand spoofing scams.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Stock Spam: A Classic Scam

Ever since there have been stocks and shares there have been so called "pump 'n' dump" scams. This...

Spyware: Know Your Enemy

Like Macavity, the fictional feline in T. S. Eliot's well-known poem, spyware may be considered to...

The Online Shadow Economy: A Billion Dollar Market For Malware Authors

Malware, meaning computer viruses, trojans and spyware, is about money. The teenagers who wrote...

Webcasts

SQL Server Consolidation: Insights from customers, analysts & HP

Microsoft SQL Server has enjoyed phenomenal success as a database server. Its relatively low cost,...

Minimizing the Risk of Information Security Breaches: Best Practices for SOA Governance and Compliance - Live October 21

Today's enterprises face more information security risks and vulnerabilities than ever before....

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Special Reports

Unified Threat Management from CheckPoint

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.