Skip to content
MailRoute
Company News

MailRoute Identifies PayPal Invoice Phishing Scam

3 min read

By CS Warren · Director of Customer Support, MailRoute

VENICE, CA — December 12, 2024

MailRoute has identified a fraud campaign that sends real PayPal invoices carrying attacker-controlled phone numbers. The messages are genuine, which is exactly what makes them work.

The scheme does not forge PayPal. It uses PayPal. An attacker creates a legitimate invoice through PayPal's own invoicing system and places a fake customer-service phone number in the note or memo field. PayPal then sends the invoice from its own servers, correctly signed. A recipient who calls the number reaches the attacker, who works to extract card details, account credentials, or remote access to the machine.

Why the Messages Pass Authentication

Most phishing detection starts by asking whether a message is really from who it claims to be. Here, it is.

  • The invoice originates from PayPal's own sending infrastructure.
  • The DKIM signature is valid, because PayPal signed it.
  • SPF and DMARC evaluate correctly, because the sending domain is genuinely PayPal's.
  • Many of the messages are then forwarded through major cloud mail providers, adding a second layer of trusted-sender reputation.

Nothing in the envelope is forged. The fraud lives entirely in the free-text field a human reads, and the payload is a phone number rather than a link or an attachment. Detection tuned for spoofed senders, malicious URLs, or hostile files has nothing to grab.

"This is not a typical phishing message, and treating it as one is how it gets through," said CS Warren, Director of Customer Support at MailRoute. "The fraudsters found a way to send through systems everyone already trusts. The attack is a phone number in a legitimate invoice, and the last line of defense is the person reading it."

What Recipients Should Do

The countermeasures are behavioral, because the message itself is authentic:

  1. Never call a phone number printed in a PayPal invoice or seller's note. Attacker-supplied numbers are the entire mechanism.
  2. Verify any charge by signing in to PayPal directly, through a manually typed address, not through the message.
  3. Use only the contact numbers published on PayPal's own site if support is needed.
  4. Report the invoice through PayPal's fraud reporting process so the sending account can be closed.

MailRoute is tuning detection against this pattern and has raised the forwarded-message and invoice-abuse cases with the platforms involved. MailRoute customers who receive one of these invoices are asked to report it to PayPal and to forward a copy to MailRoute support, which improves detection for everyone on the platform.

About MailRoute

MailRoute has provided hosted email filtering since 2003, protecting inbound and outbound mail for organizations running their own mail servers and for those on hosted platforms. Founder Thomas A. Johnson has worked in email security since 1997, when he built Big Fish Communications — later renamed FrontBridge Technologies — which Microsoft acquired in 2005 and still operates today as Exchange Online Protection. MailRoute serves organizations across regulated industries, including defense contractors operating under federal requirements.


Media contact: info@mailroute.net

Protect your email — try MailRoute free

30-day free trial. No credit card required. Full protection from day one.