PayPal Scam Alert: New Invoice Scheme Bypasses Email Security

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 
March 10, 2025 3 min read

PayPal Scam Warning—Dangerous Invoice Bypasses Email Security

Beware of a new PayPal invoice scam that uses old tricks to bypass email security. As Google rolls out AI-powered protections to aid Android users, scammers are reverting to methods that exploit email vulnerabilities. “PayPal scammers are using an old Docusign trick to enhance the trustworthiness of their phishing emails,” said Pieter Arntz, a malware intelligence researcher at Malwarebytes. Scammers set up Docusign accounts and use its templates to create seemingly legitimate invoices from PayPal. These documents come from Docusign, allowing them to slip past email security filters, making them particularly dangerous. Docusign investigates and closes suspicious accounts within 24 hours of detection. PayPal emphasizes its commitment to security, urging customers to remain vigilant and visit PayPal.com for safety tips.

PayPal Attack Red Flags To Watch For

A recent Malwarebytes report highlights several red flags in this scam campaign. Emails may appear to be from Docusign but could originate from fake Gmail addresses. “If it seems weird that Docusign has been used to send a document that doesn’t require a signature, it’s a red flag,” Arntz noted. Jamie Beckland, chief product officer at APIContext, warns that this Docusign scam uses APIs to bypass email security and steal login credentials. “All API owners should monitor APIs for suspicious behavior,” Beckland advises.

Mitigating The PayPal Docusign Attack

To mitigate the risk, if you receive a suspicious email claiming to be from Docusign, verify its authenticity directly on Docusign.com by clicking the Access Documents link. Enter the document security code provided in the email. If you receive an error, the document may be fraudulent. Always check your PayPal account directly, not via links in emails, for any unauthorized transactions. Report any suspicious activity to both PayPal and Docusign.

How PayPal Protects Users From Scams As Attacks Evolve

PayPal employs a combination of manual investigations and advanced technologies to protect users. They limit scam accounts and decline risky transactions. PayPal's evolving fraud detection tools include reminders for customers about suspicious invoices and payment requests. Customers should:

  • Avoid calling phone numbers or clicking links in suspicious messages.
  • Change their account password and contact PayPal if they suspect phishing.
  • Enable two-factor authentication or use a Passkey.
  • Report suspicious messages directly to email providers.
  • Contact law enforcement to report scams.

For more information about invoice and money request scams, visit the PayPal US security page. image of an invoice containing an alarmist note Image courtesy of PayPal image of a scam email containing an alarmist note Image courtesy of PayPal

Cybersecurity Marketing Solutions

In response to the constantly evolving threats in the digital landscape, GrackerAI offers AI-powered cybersecurity marketing solutions. Our platform helps organizations transform security news into strategic content opportunities. By automating insight generation from industry developments, GrackerAI positions itself as a powerful tool for creating timely, relevant marketing materials that resonate with cybersecurity professionals and decision-makers. To explore our services or contact us, visit GrackerAI.

Latest Cybersecurity Trends & Breaking News

Amazon and Microsoft Battle for Quantum Computing Supremacy Amidst Industry Challenges AI Arms Race and Malware Development

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 

Cybersecurity veteran and serial entrepreneur who built GrackerAI to solve the link between B2B SaaS product and search engine. Leads the mission to help cybersecurity brands dominate search results through AI-powered product-led ecosystem.

Related Articles

growth hacking

What is Growth Hacking and How Can You Master It?

Learn growth hacking: definition, core principles, skills, and practical strategies to master growth for B2B SaaS and cybersecurity. Real-world examples included!

By Govind Kumar September 14, 2025 11 min read
Read full article

100 SEO Resources I (Probably) Can’t Live Without

Unlock your SEO potential with 100 essential resources. This actionable list, built over 12 years, reveals tried-and-tested tools and insights to elevate your strategy.

By Ankit Lohar September 14, 2025 45 min read
Read full article
social media aggregators

How Social Media Aggregators Drive B2B Engagement and SEO Results

Learn how social media aggregators drive B2B engagement, boost SEO rankings, build trust with social proof, and enhance brand visibility.

By Ankit Agarwal September 13, 2025 3 min read
Read full article
website authority

How to Check a Website’s Authority Before Building Links

Learn how to check website authority before link building. Discover DA, DR, spam score, and tips to build safe, high-quality backlinks.

By Nikita Shekhawat September 13, 2025 4 min read
Read full article