logo

PayPal Phishing

ID: d78c1bd3-332b-5374-8938-e59a7bf46668

STIX ID: report--d78c1bd3-332b-5374-8938-e59a7bf46668

Feed Name: WatchGuard Secplicity Blog

Threat Score
50/100

Date Published: 2020-05-04

Date Updated: 2026-05-01

Author: The Editor

...
...

This report analyzes a PayPal-branded phishing campaign that used a URL shortener and newly-registered attacker domains (examples: phonedisney.com, meansfat.com, service-account.genuinelysmash.com) to collect login credentials, full PII (name, address, phone, SSN, mother’s maiden name) and validated credit-card details; the phish employed session-bound keys to prevent repeated analysis and ultimately redirected victims to the real PayPal site, and the author notes DNSWatch blocks these domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.