The Newest Paypal Scam on the Block

Scam emails have been going around since email was invented, and they’ll probably keep circulating as long as email is in use. They’ll also keep changing form. At first, email scams didn’t need any sort of legitimacy to get some people – an email would come in from “[email protected]”, telling you that “Jake” works for the power company and you need to remit a check to an address that isn’t the power company, and that alone would get some people. When the power company gets its own special domain, @powercompany.com, the odds are good that another, similar domain, like @powrcompany.com or @powerconpany.com, is available for purchase – and then that gets people for a while.

On and on we go.

Now, we’ve gotten to a point where scammers are figuring out tricks to use legitimate emails to send scams. The newest scam hitting the open web is one where someone sends you a penny in PayPal. This is no cause for alarm by itself – your email, while not strictly public info, is much more available to many more data brokers than, say, a password. The problem is that the person sending the penny can attach a custom message to it, and that’s where people may get tripped up. For example, someone sends a penny with the message “You’re being charged XXX.XX$. Call (Some Random Phone Number) to cancel”, which is what Paypal then puts in the message header when it tells you that you have received a penny. You don’t read that you have received money, you just see a seemingly legit email – from PayPal, because PayPal did send the email! – telling you that you’ve been charged some absurd amount of money. If you don’t take a second to read more thoroughly, or you don’t fully understand how the PayPal notification systems work, this may fool you!

You sometimes don’t even get a whole penny: other currencies have denominations that make up fractions of the worth of a U.S. penny, further confusing the person who received the email and may have even opened it trying to figure out what happened. Why is a Hungarian lyra mentioned in this email? Did they get hacked? Et cetera. Any time you’re worried you may have gotten money taken from you, remember that you can always check in a separate window. Do NOT EVER open links from a suspicious email! Open a separate page, and then visit the service or website you’re worried about by typing the address into the URL bar (NOT by clicking any link in the email or text), signing in, and then looking over your statements yourself to determine whether or not you’re actually being defrauded, or if someone is trying to scare you into giving up your data.