Chops
Active Member
PayPal took action on Friday to close down a telephone number used in a new type of phishing scam designed to steal account information from unsuspecting customers.
According to Sara Bettencourt, a PayPal spokesperson, the scam worked by criminals sending an offical-looking e-mail to PayPal users around the world, requesting that they call an account-verification phone number to update key account details.
"The phishers never stop innovating when it comes to social-engineering techniques," said Avivah Litan, an analyst at Gartner.
"This new one gets around consumer fears of clicking on URLs embedded within e-mails, and the criminals are likely to get a higher response rate than the typical 3 percent they get with URL-based e-mail scams," she noted.
Phone Scam
Through Voice over Internet Protocol (VoIP) services, such as Skype or Vonage, it is relatively easy to obtain a local telephone number without having any physical location tied to it. Phishers then build bogus telephone systems around the number to mimic those of genuine online-banking organizations, said Graham Cluley, a senior consultant at security firm Sophos.
"Consumers accept that many online companies won't have a local number to call when you need help," he said. "When it's something as important as a security issue with your account, that'll be a strong incentive to the unguarded to make the call."
The latest scam to hit PayPal was doubly innovative. In addition to using an official-sounding telephone tree, the e-mail was able to make it through spam filters to many inboxes because it was sent out as an image -- containing no actual words in the message.
"This is done by the phishers to try and circumvent less sophisticated antispam filters, which may try and block e-mails based upon the text content or links contained inside the message," said Cluley.
PayPal Cover
While the scam might sound serious, there is good news for any concerned PayPal users, and particularly for those who did call the number and go through the fake account-verification process.
"PayPal will always reimburse all its users worldwide for unauthorized use of the PayPal account," said Bettencourt, who recommended that if customers entered their account details after calling the bogus telephone number, they should log in on the PayPal site and change their passwords.
Diane Shaib, executive vice president of Orbiscom, a security company specializing in online-payment systems, noted that PayPal is among the top five U.S. financial services Web sites that get targeted by phishers.
"PayPal is extremely vigilant in taking steps to shut down phishing Web sites," said Shaib. "The problem is that there is always going to be a very small percentage of people who receive phishing e-mails and respond to them."