Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
How To Talk To AI

How To Talk To AI

10 June 2026
America’s emergency oil reserve is about to hit its lowest level since Reagan was in office

America’s emergency oil reserve is about to hit its lowest level since Reagan was in office

10 June 2026
See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky

See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky

10 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » PayPal Security Warning—$2,000 ‘Phish-Free’ Phishing Attack Confirmed
Innovation

PayPal Security Warning—$2,000 ‘Phish-Free’ Phishing Attack Confirmed

Press RoomBy Press Room9 January 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
PayPal Security Warning—,000 ‘Phish-Free’ Phishing Attack Confirmed

When is a phishing attack not a phishing attack? That is the question posed by Fortiguard’s chief information security officer after he was targeted by a new attack using a legitimate PayPal feature from a legitimate address with a seemingly legitimate URL as well. Here’s what you need to know about the “phish-free” PayPal phishing attack.

The Evolution Of Phishing Attacks—PayPal Users Now In The Crosshairs

Phishing attacks are getting ever more clever in their approach, as a recent news article highlighting how genuine Google security prompts are being used to scam victims to give up their account credentials revealed. While the do-not-click advice is, as always, the baseline for anti-phishing best practices, it’s no longer good enough when legitimate features are being exploited by hackers in no-phish phishing attackers. Let this example of just such an attack, using legitimate PayPal functionality, be a warning to you: if the CISO of a security company thinks it’s highly dangerous then so should you.

“A genuine email can’t still be a problem, can it?” That’s the question that Fortiguard chief information security officer, Dr. Carl Windsor, posed in a new warning posted to the Fortiguard Labs Threat Research blog, Jan. 8. Reporting how the email in question, purporting to be from PayPal and “the sender address appears to be valid and not spoofed,” and using a genuine PayPal money request feature, could fool his mother, the standard test he uses in such circumstances, Windsor warned that the attack “doesn’t use traditional phishing methods.” In fairness, it sounds pretty fishy to me so far, but let’s explore further to see what Windsor means.

The No-Phish PayPal Phishing Scam

“The email, the URLs, and everything else is perfectly valid,” Windsor explained, and when you click on the link (don’t do that,) the victim is redirected to a PayPal login page showing a request for payment. The trick being employed by the attackers here is that your PayPal account address is linked to the address it was sent to rather than the one it was received at. The victim might not notice that the email was addressed to a user who had registered a free Microsoft 365 test domain to create the distribution list that contained the target emails. By then using the legitimate PayPal payment request feature and using this list as the recipient address, everything looked completely legitimate. Apart from the to: address field, which the victim can easily miss unless they happen to be a chief information security officer, or at least you’d hope not. The payment request, in this case, was for $2,185.96 which is large enough to be profitable at scale yet “small” enough not to raise too much suspicion for many corporate targets.

Mitigating The PayPal Phishless Phish Attack

“The best solution is the Human Firewall,” Windsor said, “someone who has been trained to be aware and cautious of any unsolicited email, regardless of how genuine it may look.”

Elad Luz, head of research at Oasis Security, meanwhile, warned that exploiting a vendor feature and sending from a verified source makes these attacks “difficult for mailbox providers to distinguish from genuine communications, leaving PayPal as potentially the only entity capable of mitigating the issue.”

I have reached out to PayPal for a statement.

Fortiguard fraud Money PayPal alert PayPal attack PayPal fraud PayPal hack PayPal phishing PayPal security warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

How To Talk To AI

How To Talk To AI

10 June 2026
See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky

See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky

10 June 2026
Best Highlights And Biggest Wins

Best Highlights And Biggest Wins

10 June 2026
The Hearts & Minds Driving Regional Expansion

The Hearts & Minds Driving Regional Expansion

10 June 2026
Anthropic Ships Its Strongest Model Then Rations Access

Anthropic Ships Its Strongest Model Then Rations Access

10 June 2026
NYT ‘Pips’ Hints, Answers And Walkthrough For Wednesday, June 10

NYT ‘Pips’ Hints, Answers And Walkthrough For Wednesday, June 10

10 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Europe wants sovereign AI, but most of the chips are from the U.S.

Europe wants sovereign AI, but most of the chips are from the U.S.

10 June 20262 Views
The Hearts & Minds Driving Regional Expansion

The Hearts & Minds Driving Regional Expansion

10 June 20262 Views
FIFA says ‘market rates’ explain World Cup prices. Economists say the market was rigged by design

FIFA says ‘market rates’ explain World Cup prices. Economists say the market was rigged by design

10 June 20262 Views
Anthropic Ships Its Strongest Model Then Rations Access

Anthropic Ships Its Strongest Model Then Rations Access

10 June 20262 Views

Recent Posts

  • How To Talk To AI
  • America’s emergency oil reserve is about to hit its lowest level since Reagan was in office
  • See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky
  • Best Highlights And Biggest Wins
  • Europe wants sovereign AI, but most of the chips are from the U.S.

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
How To Talk To AI

How To Talk To AI

10 June 2026
America’s emergency oil reserve is about to hit its lowest level since Reagan was in office

America’s emergency oil reserve is about to hit its lowest level since Reagan was in office

10 June 2026
See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky

See Venus And Jupiter’s Brilliant ‘Kiss’ In The Night Sky

10 June 2026
Most Popular
Best Highlights And Biggest Wins

Best Highlights And Biggest Wins

10 June 20262 Views
Europe wants sovereign AI, but most of the chips are from the U.S.

Europe wants sovereign AI, but most of the chips are from the U.S.

10 June 20262 Views
The Hearts & Minds Driving Regional Expansion

The Hearts & Minds Driving Regional Expansion

10 June 20262 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.