Watch out - that urgent PayPal email could be a phishing scam

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
(Image credit: weerapatkiatdumrong / Getty Images)

A new warning issued by the Federal Trade Commission (FTC) has urged internet users to be wary of new phishing email scams, supposedly coming from payment gateway PayPal and crypto wallet platform MetaMask.

The PayPal email warns customers that BNC Billings has canceled their payment to Binance, while the MetaMask email informed customers that their cryptocurrency wallet has been blocked.

Both are scams, and the FTC is asking that recipients forward such emails to reportphishing@apwg.org. They should not interact with the email, and delete it immediately.

PayPal and MetaMask phishing emails

The convincing email supposedly from PayPal is decorated with legitimate colors, logos, and fonts. It also includes a dud invoice, and in the body of the email is a phone number that links directly to the scammer who proceeds to ask unsuspecting customers for sensitive information, such as account passwords, payment detail information, and personal information.

Twitter user OF24com describes how the invoice appears to use the legitimate PayPal domain, helping to persuade even the savviest of PayPal users to share their information. 

While the PayPal phishing email uses alarming prices to frighten customers into action, the MetaMask scam employs a sense of urgency. The email reads:

“Due to the dramatic increase in our platform users, some wallets still need to manually perform the new upgrade. You must upgrade your wallets before [date] in order to keep your assets secure and accessible.”

In an effort to protect citizens, the FTC is advising victims to “slow down” and to assess the email and their circumstances more carefully. The advice is also not to click on any links - if a company has shared a message with you, you will usually be able to find it on the website, in your account (accessed directly via the website), or by phoning the company (again, directly from its website). Contact details shared in an email may not belong to the company in question.

Other general advice includes downloading and updating malware removal tools and endpoint protection software.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
PayPal
This PayPal scam exploits new address feature to send out phishing scam emails
Paper craft illustration of a suspicious email that contains a snake
How to spot a phishing email
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
Shopping scams
New wave of sextortion scams uses personal details and images to intimidate targets while bypassing traditional security measures
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
girl using laptop hoping for good luck with her fingers crossed
Windows 11 24H2 seems to be a massive fail – so Microsoft apparently working on 25H2 fills me with hope... and fear
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
ChatGPT Advanced Voice mode on a smartphone.
Talking to ChatGPT just got better, and you don’t need to pay to access the new functionality
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Apple Watch Ultra 2 timer
The Apple Watch is getting a sleep alarm upgrade it probably should have had 10 years ago