Scammers exploited a loophole in PayPal’s subscription management feature to send legitimate emails from the official service@paypal.com address, tricking recipients with fake purchase notifications. By creating and then pausing a PayPal subscription, attackers triggered authentic PayPal notifications stating that an automatic payment was no longer active. These emails were manipulated to include alarming messages about expensive purchases and embedded fake customer support phone numbers, prompting recipients to call for assistance.
The scam leveraged Unicode characters and formatting tricks to evade spam filters, making the emails appear more credible and difficult to detect. Victims who called the provided numbers were subjected to classic tech support fraud tactics, including remote access attempts and efforts to extract sensitive information or install malicious software. Following public reporting and investigation, PayPal closed the loophole to prevent further abuse of its email notification system for phishing and social engineering attacks.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A PayPal-themed scam used legitimate one-cent transactions, apparently tied to "Demetrus Techeck LLC," to place alarming messages in victims' accounts claiming a third-party wallet had been linked and a $980 payout was imminent. The messages urged targets to call a fake customer-service number connected to scammers, representing a different abuse method from the earlier subscription-email scheme.
By the following day, PayPal had closed the loophole that allowed scammers to trigger legitimate-looking purchase-related emails through its subscription feature. This action ended the specific abuse path described in the reports.
PayPal confirmed it was aware of the abuse, advised customers to use only official support channels, and said it was actively mitigating the problem. At that stage, the company had not publicly provided technical details of the fix.
Reporting revealed the campaign used a forwarding setup, likely a Google Workspace mailing list, to distribute the PayPal-generated emails to many victims. The scam then pushed recipients to call fake support, where operators attempted remote-access and tech-support fraud to steal money or data.
Scammers began exploiting PayPal's subscription and automatic payment notification workflow to generate genuine emails from service@paypal.com that referenced bogus expensive purchases and included fraudulent support phone numbers. The messages passed standard email authentication checks because they were sent from PayPal's own infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourcemalwarebytes.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.