Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Stop talking to AI, let them talk to each other: The A2A protocol

    Swedish pet insurtech Lassie raises $75M Series C after hitting $100M ARR

    Understanding the valuation of intangible assets in tech deals

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025
    • Crypto

      Berachain Jumps 150% as Strategic Pivot Lifts BERA

      February 12, 2026

      Tom Lee’s BitMine (BMNR) Stock Faces Cost-Basis Risk — Price Breakdown at 10%?

      February 12, 2026

      Why the US Jobs Data Makes a Worrying Case for Bitcoin

      February 12, 2026

      MYX Falls Below $5 as Short Sellers Take Control — 42% Decline Risk Emerges

      February 12, 2026

      Solana Pins Its $75 Support on Short-Term Buyers — Can Price Survive This Risky Setup?

      February 12, 2026
    • Technology

      Stop talking to AI, let them talk to each other: The A2A protocol

      February 13, 2026

      Swedish pet insurtech Lassie raises $75M Series C after hitting $100M ARR

      February 13, 2026

      Understanding the valuation of intangible assets in tech deals

      February 13, 2026

      The Asus Zenbook S 16 Is $500 Off and Has Never Been This Cheap

      February 13, 2026

      ‘Uncanny Valley’: ICE’s Secret Expansion Plans, Palantir Workers’ Ethical Concerns, and AI Assistants

      February 13, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Beware: PayPal subscriptions abused to send fake purchase emails
    Technology

    Beware: PayPal subscriptions abused to send fake purchase emails

    TechAiVerseBy TechAiVerseDecember 15, 2025No Comments5 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Beware: PayPal subscriptions abused to send fake purchase emails
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Beware: PayPal subscriptions abused to send fake purchase emails

    An email scam is abusing abusing PayPal’s “Subscriptions” billing feature to send legitimate PayPal emails that contain fake purchase notifications embedded in the Customer service URL field.

    Over the past couple of months, people have reported [1, 2] receiving emails from PayPal stating, “Your automatic payment is no longer active.” 

    The email includes a customer service URL field that was somehow modified to include a message stating that you purchased an expensive item, such as a Sony device, MacBook, or iPhone.

    This text includes a domain name, a message stating that a payment of $1,300 to $1,600 was processed (the amount varies by email), and a phone number to cancel or dispute the payment. The text is filled with Unicode characters that make portions appear bold or in an unusual font, a tactic used to try and evade spam filters and keyword detection.

    “http://[domain] [domain] A payment of $1346.99 has been successfully processed. For cancel and inquiries, Contact PayPal support at +1-805-500-6377,” reads the customer service URL in the scam email.

    PayPal subscription email used in scam
    Source: BleepingComputer

    While this is clearly a scam, the emails are being sent directly by PayPal from the address “service@paypal.com,” leading people to worry their accounts may have been hacked.

    Furthermore, as the emails are legitimate PayPal emails, they are bypassing security and spam filters. In the next section, we will explain how scammers send these emails.

    The goal of these emails is to trick recipients into thinking their account purchased an expensive device and scare them into calling the scammer’s “PayPal support” phone number.

    Emails like these have historically been used to convince recipients to call a number to conduct bank fraud or trick them into installing malware on their computers.

    Therefore, if you receive a legitimate email from PayPal stating your automatic payment is no longer active, and it contains a fake purchase confirmation, ignore the email and do not call the number.

    If you are concerned that your PayPal account was compromised, log in to your account and confirm that there was no charge.

    How the PayPal scam works

    BleepingComputer was sent a copy of the email from someone who received it and found it strange that the scam originated from the legitimate “service@paypal.com” email address.

    Furthermore, the email headers indicate that the emails are legitimate, pass DKIM and SPF email security checks, and originate directly from PayPal’s “mx15.slc.paypal.com” mail server, as shown below.

    ARC-Authentication-Results: i=1; mx.google.com;
           dkim=pass header.i=@paypal.com header.s=pp-dkim1 header.b="AvY/E1H+";
           spf=pass (google.com: domain of service@paypal.com designates 173.0.84.4 as permitted sender) smtp.mailfrom=service@paypal.com;
           dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=paypal.com
    Received: from mx15.slc.paypal.com (mx15.slc.paypal.com. [173.0.84.4])
            by mx.google.com with ESMTPS id a92af1059eb24-11dcb045a3csi5930706c88.202.2025.11.28.09.14.49
            for 
            (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
            Fri, 28 Nov 2025 09:14:49 -0800 (PST)

    After testing various PayPal billing features, BleepingComputer was able to replicate the same email template by using PayPal’s “Subscriptions” feature and pausing a subscriber.

    PayPal subscriptions are a billing feature that lets merchants create subscription checkout options for people to subscribe to a service for a specified amount. 

    When a merchant pauses a subscriber’s subscription, PayPal will automatically email the subscriber to notify them that their automatic payment is no longer active.

    However, when BleepingComputer attempted to replicate the scam by adding text other than a URL to the Customer Service URL, PayPal would reject the change as only a URL is allowed.

    Therefore, it appears the scammers are either exploiting a flaw in PayPal’s handling of subscription metadata or using a method, such as an API or legacy platform not available in all regions, that allows invalid text to be stored in the Customer service URL field.

    Now that we know how they generate the email from PayPal, it’s still unclear how it’s being sent to people who didn’t sign up for the PayPal subscription.

    The mail headers show that PayPal is actually sending the email to the address “receipt3@bbcpaglomoonlight.studio,” which we believe is the email address associated with a fake subscriber created by the scammer.

    This account is likely a Google Workspace mailing list, which automatically forwards any email it receives to all other group members. In this case, the members are the people the scammer is targeting.

    This forwarding can cause all subsequent SPF and DMARC checks to fail, since the email was forwarded by a server that was not the original sender.

    PayPal has now told BleepingComputer that they are mitigating the method used to send these scam emails.

    “PayPal does not tolerate fraudulent activity and we work hard to protect our customers from consistently evolving phishing scams,” PayPal told BleepingComputer.

    “We are actively mitigating this matter, and encourage people to always be vigilant online and mindful of unexpected messages. If customers suspect they are a target of a scam, we recommend they contact Customer Support directly through the PayPal app or our Contact page for assistance.”

    Update 12/14/25: Added updated statement confirming that PayPal is mitigating the method used to send these emails.


    Break down IAM silos like Bitpanda, KnowBe4, and PathAI

    Broken IAM isn’t just an IT problem – the impact ripples across your whole business.

    This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what “good” IAM looks like, and a simple checklist for building a scalable strategy.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleCyberVolk’s ransomware debut stumbles on cryptography weakness
    Next Article Inside the high drama of the iPhone 4
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Stop talking to AI, let them talk to each other: The A2A protocol

    February 13, 2026

    Swedish pet insurtech Lassie raises $75M Series C after hitting $100M ARR

    February 13, 2026

    Understanding the valuation of intangible assets in tech deals

    February 13, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025668 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025256 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025153 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology February 13, 2026

    Stop talking to AI, let them talk to each other: The A2A protocol

    Stop talking to AI, let them talk to each other: The A2A protocol Have you…

    Swedish pet insurtech Lassie raises $75M Series C after hitting $100M ARR

    Understanding the valuation of intangible assets in tech deals

    The Asus Zenbook S 16 Is $500 Off and Has Never Been This Cheap

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Stop talking to AI, let them talk to each other: The A2A protocol

    February 13, 20262 Views

    Swedish pet insurtech Lassie raises $75M Series C after hitting $100M ARR

    February 13, 20262 Views

    Understanding the valuation of intangible assets in tech deals

    February 13, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.