Fake PayPal Emails Cost £8million In Theft

Action Fraud is warning people selling items online to be on the lookout for criminals sending fake PayPal emails. Between January 2020 and September 2020, 21,349 crime reports were made to Action Fraud about fake PayPal emails. Victims reported losing a total of £7,891,077 during this time. Those targeted included people selling jewelry, furniture and electronics via online marketplaces. 

Reports of fake PayPal emails to Action Fraud made up a third of all reports of online shopping and auction fraud during this period.

Criminals have been targeting people selling items online, by sending them emails purporting to be from PayPal. The emails trick victims into believing they have received payment for the items they’re selling on the platform. Typically, after receiving these emails, victims will then send the item to the criminal. This leaves them at a further disadvantage having not received any payment for the item and also no longer being in possession of it.

Pauline Smith, Head of Action Fraud said: 

“We know that criminals will go to great lengths to target people on online marketplaces, especially now many more people are selling items online due to the coronavirus pandemic....Criminals have taken advantage of the coronavirus outbreak to commit fraud and will continue to do so. We are working hard, together with our partners, such as PayPal, to raise awareness of the types of scams being committed and prevent people from falling victim." 

 “It’s really important to follow our advice to help protect yourself. If you receive a suspicious email claiming you’ve received payment for an item you’re selling, take five minutes to check directly with PayPal that the communication is genuine. If something feels wrong then always question it.”

Action Fraud issued a similar warning earlier this year, after it received 3,059 crime reports about fake PayPal emails between October 2019 and December 2019.

Victims reported losing a total of £1,121,446 during this time. Reports of fake PayPal emails to Action Fraud made up almost 18% of all reports of online shopping and auction fraud during this period.

In one instance, a victim received a fake email purporting to be from PayPal claiming the buyer accidently paid more than they should have.The buyer then asked the victim to pay the difference by sending a gift card to them loaded with the difference, which they did. In another case, the fake email from PayPal claimed the buyer had accidently paid for the item twice.The buyer then asked the seller to wire the overpayment to a bank account in a different country.

What Do You Need To Do?

  • Sellers beware: If you’re selling items on an online marketplace, be aware of the warning signs that your buyer is a scammer. Scammers may have negative feedback history, or may have recently set up a new account to avoid getting poor feedback. Don’t be persuaded into sending anything until you can verify you’ve received the payment.
     
  • Scam messages: Don’t click on the links or attachments in suspicious emails, and never respond to messages that ask for your personal or financial details.

If you think you’ve been a victim of fraud, report it to Action Fraud online at actionfraud.police.uk or by calling 0300 123 2040.

A spokesperson for PayPal, said:

“At PayPal we go to great lengths to protect our customers in the UK, but there are still a few simple precautions we should all take to avoid falling victim to scams... All communications from PayPal to account holders would be sent to the secure message centre within their PayPal account. You will have a secure message waiting if PayPal does need you to take any action... A genuine PayPal email will only ever address you by your full name, anything that starts differently should immediately raise your suspicions. Look out for spelling mistakes, which are a common tell-tale sign of a fraudulent message.”

If you think that you’ve received a suspicious email, you can forward it to PayPal, without changing the subject line. PayPal will let you know whether it is fraudulent or not

PayPal:       Action Fraud:          Gedling Eye:     South Wales Argus:       Birmingham Mail:   

You Might Also Read:

Online Shoppers Have Lost Over £16m To Lockdown Fraud:

 

« British National Cyber Security Guidance
Cyber Security For Home Working »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

JYVSECTEC - JAMK University of Applied Sciences

JYVSECTEC - JAMK University of Applied Sciences

JYVSECTEC is a cyber security research and development and training centre

Juniper Networks

Juniper Networks

Juniper Networks is the industry leader in network innovation. We provide network infrastructure and network security solutions.

Eden Legal

Eden Legal

Eden Legal provides legal services on commercial and regulatory issues affecting digital businesses.

DMH Stallard

DMH Stallard

DMH Stallard is a mid-market law firm. Areas of expertise include cyber security and cyber crime.

MarQuest

MarQuest

MarQuest provides services and systems to enhance network reliability and security.

QTS

QTS

QTS Realty Trust, Inc. is a leading provider of secure, compliant data center, hybrid cloud and managed services.

Aves Netsec

Aves Netsec

Aves is a deceptive security system for enterprises who want to capture, observe and mitigate bad actors in their internal network.

Wizlynx Group

Wizlynx Group

Wizlynx services cover the entire risk management lifecycle from security assessments and compliance to the implementation of security solutions and provision of Managed Security Services.

Cryptsoft

Cryptsoft

Cryptsoft provides key management and security software development toolkits based around open standards such as OASIS KMIP and PKCS#11.

CybExer Technologies

CybExer Technologies

CybExer provide an on-premise, easily deployable solution for complex technical cyber security exercises based on experience in military grade ranges.

Deft

Deft

Deft (formerly ServerCentral Turing Group) is a trusted provider of colocation, cloud, and disaster recovery services.

NewAE Technology

NewAE Technology

NewAE Technology is revolutionizing the hardware security market by making every engineer and designer aware of side-channel power analysis and glitching as important attack vectors.

Fairdinkum Consulting

Fairdinkum Consulting

Fairdinkum is a leading full-service IT consulting firm with more than two decades of experience in the industry.

Modern Networks

Modern Networks

Modern Networks is a leading provider of IT managed services to the UK’s commercial property sector and medium sized enterprises.

Communications Fraud Control Association (CFCA)

Communications Fraud Control Association (CFCA)

CFCA is the premier International Association for fraud risk management, fraud prevention and profitability control.

Couno

Couno

Couno is a trusted provider of IT support services throughout the UK and Europe.