logo

The PayPal Invoice That Passed Every Check Because PayPal Actually Sent It

ID: 988e69de-30a7-5684-8c87-7a542ee4ee2b

STIX ID: report--988e69de-30a7-5684-8c87-7a542ee4ee2b

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (Audian Paxson)

...
...

A PayPal invoice-cancellation phishing campaign used legitimately authenticated PayPal-sent emails (SPF/DKIM/DMARC passed) with all links pointing to PayPal pages, while the Reply-To header directed responses to a merchant domain controlled by the attacker; behavioral detection (IRONSCALES/Themis) flagged it and community validation confirmed phishing. The report provides IOCs ([email protected], [email protected], kissimmeenotarypublic.com, 173.0.84.6, d=paypal.com s=pp-dkim1) and recommends verifying Reply-To headers before replying to invoices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.