logo

Exposing Qwiklabs Email Misuse in Sneaky Payment Scams involving setting up UPI merchant accounts

ID: 54d25b03-8d4d-5404-b64a-56c43d543d42

STIX ID: report--54d25b03-8d4d-5404-b64a-56c43d543d42

Feed Name: CloudSEK Blog

Date Published: 2024-01-17

Date Updated: 2026-04-27

...
...

CloudSEK details a payment fraud vector where attackers exploit Qwiklabs temporary Gmail access to register Google Pay merchant accounts without phone verification, enabling brand impersonation and deceptive UPI VPAs/mandates that appear legitimate to victims; the report outlines the workflow, attacker advantages, user safety steps, and recommended controls for payment providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.