Australia markets closed
  • ALL ORDS

    6,865.30
    +18.00 (+0.26%)
     
  • ASX 200

    6,634.10
    +18.80 (+0.28%)
     
  • AUD/USD

    0.7427
    -0.0013 (-0.17%)
     
  • OIL

    46.09
    +0.45 (+0.99%)
     
  • GOLD

    1,842.00
    +0.90 (+0.05%)
     
  • BTC-AUD

    25,298.96
    -50.90 (-0.20%)
     
  • CMC Crypto 200

    365.19
    -14.05 (-3.71%)
     
  • AUD/EUR

    0.6123
    +0.0001 (+0.02%)
     
  • AUD/NZD

    1.0529
    +0.0018 (+0.17%)
     
  • NZX 50

    12,631.38
    -17.53 (-0.14%)
     
  • NASDAQ

    12,528.48
    +61.35 (+0.49%)
     
  • FTSE

    6,550.23
    +59.96 (+0.92%)
     
  • Dow Jones

    30,218.26
    +248.74 (+0.83%)
     
  • DAX

    13,298.96
    +46.10 (+0.35%)
     
  • Hang Seng

    26,835.92
    +107.42 (+0.40%)
     
  • NIKKEI 225

    26,751.24
    -58.13 (-0.22%)
     

'Crafted to steal': 7 million Australians at risk of online threat

Jessica Yun
·3-min read
A new Paypal scam is doing the rounds. (Source: Mailguard, Getty)
A new Paypal scam is doing the rounds. (Source: Mailguard, Getty)

Australians have been warned again to be on alert for another Paypal scam that they may find in their inboxes.

According to email security firm Mailguard, a malicious email that looks like it’s from the global payments system notifies victims that some “unusual activity on your Paypal” has been “detected”.

But it’s a phishing scam aimed at harvesting people’s personal and banking data, Mailguard said in a blog post.

This comes about a week after Mailguard issued its last scam alert, which warned users of ‘Suspicious Login Activity’ but also designed to steal sensitive information.

According to its website, Paypal has more than 7 million users in Australia.

Users are told of concerns about “potential unauthorised access”, and that their account has been “temporarily limited” as a result.

“For your .Safety [sic], we have temporarily limited your account. until you take action,” the email reads.

Recipients are then instructed to log into their Paypal accounts and complete steps to “secure your account”.

(Source: Mailguard)
(Source: Mailguard)
(Source: Mailguard)
(Source: Mailguard)

The unwitting victim is then taken to a fake login page, which then leads to several phishing pages that ask for:

  • Credit card details;

  • Address;

  • Banking details and identifiers;

  • Email details; and

  • Pictures of various documents used for verifying identity, including passport, national ID and driver’s license.

(Source: Mailguard)
(Source: Mailguard)
(Source: Mailguard)
(Source: Mailguard)
(Source: Mailguard)
(Source: Mailguard)

What to look out for

To catch the scam, there are multiple give-away signs, including poor grammar and spelling; generic greetings, or failing to address users by name; and URLs that don’t direct to where they are purported to go.

If you hear from a business you weren’t expecting to, it pays to be on the safe side and stay cautious about the notification.

However, cyber criminals will try to trap users through an alarming subject line and body, good quality logos and branding, and other language that demands users take action immediately.

‘Grave consequences’

“Most of these pages are designed to appear as legitimate pages belonging to PayPal, employing high-quality branding and styling elements,” said Mailguard.

“They are crafted to steal a wide variety of personal information from users and could lead to grave consequences.”

Anyone who falls for the scam will have their Paypal accounts hijacked and details and identity stolen.

“Scams that are initiated from compromised accounts (like in this case) are particularly dangerous because the emails are sent from a legitimate account, so they are not likely to be blocked by email security services. Cybercriminals often exploit these rules to trick users.”

Paypal’s global brand makes it popular among cyber criminals, especially in the context of the rise of online shopping amid the Covid-19 pandemic.

“All that it takes to break into your business is a cleverly-worded email message. If scammers can trick one person in your company into clicking on a malicious link they can gain access to your data,” Mailguard said.

You can report scams to Scamwatch, as well as to the implicated institution.

Want to get better with money and investing in 2021? Sign up here to our free newsletter and get the latest tips and news straight to your inbox.

Follow Yahoo Finance Australia on Facebook, Twitter, Instagram and LinkedIn.