Cybercriminals are distributing bulk phishing emails that impersonate well-known brands such as PayPal and HP to execute tech support scams. In one campaign, recipients receive a fake PayPal invoice from a Gmail address, with the email BCC'd to many targets and containing a suspicious attachment. The invoice claims the recipient has been billed $823 and urges them to call a phone number to dispute the charge, a tactic designed to create urgency and lure victims into contacting the scammers directly. The email passes SPF, DKIM, and DMARC checks because it originates from a legitimate Gmail server, but the sender address and lack of branding are clear indicators of fraud.
A similar scam involves emails purporting to be from HP, including a PDF attachment and instructing recipients to call a provided phone number. The phone number connects to a generic call center that does not mention HP and instead attempts to engage the victim in a warranty renewal scam. These callback phishing schemes often use phone numbers that appear in multiple scam reports online and are answered by operators trained to adapt their script based on the brand the victim mentions. Both scams exploit technical authentication checks and social engineering to bypass suspicion and trick users into divulging sensitive information or making payments.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes reported a tech support scam in which attackers used a fake PayPal invoice themed around Geek Squad to trick targets. No separate incident date is given in the reference, so the publication date is used.
KnowBe4 published a report discussing whether a scam campaign impersonating HP was legitimate or fraudulent, indicating active circulation of HP-themed scam messages. No earlier event date is provided in the reference, so the publication date is used as the event date.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.