PayPal Scam Alert: New Invoice Scheme Bypasses Email Security

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 
March 10, 2025 3 min read

PayPal Scam Warning—Dangerous Invoice Bypasses Email Security

Beware of a new PayPal invoice scam that uses old tricks to bypass email security. As Google rolls out AI-powered protections to aid Android users, scammers are reverting to methods that exploit email vulnerabilities. “PayPal scammers are using an old Docusign trick to enhance the trustworthiness of their phishing emails,” said Pieter Arntz, a malware intelligence researcher at Malwarebytes. Scammers set up Docusign accounts and use its templates to create seemingly legitimate invoices from PayPal. These documents come from Docusign, allowing them to slip past email security filters, making them particularly dangerous. Docusign investigates and closes suspicious accounts within 24 hours of detection. PayPal emphasizes its commitment to security, urging customers to remain vigilant and visit PayPal.com for safety tips.

PayPal Attack Red Flags To Watch For

A recent Malwarebytes report highlights several red flags in this scam campaign. Emails may appear to be from Docusign but could originate from fake Gmail addresses. “If it seems weird that Docusign has been used to send a document that doesn’t require a signature, it’s a red flag,” Arntz noted. Jamie Beckland, chief product officer at APIContext, warns that this Docusign scam uses APIs to bypass email security and steal login credentials. “All API owners should monitor APIs for suspicious behavior,” Beckland advises.

Mitigating The PayPal Docusign Attack

To mitigate the risk, if you receive a suspicious email claiming to be from Docusign, verify its authenticity directly on Docusign.com by clicking the Access Documents link. Enter the document security code provided in the email. If you receive an error, the document may be fraudulent. Always check your PayPal account directly, not via links in emails, for any unauthorized transactions. Since many users rely on PayPal to both receive and access their funds, knowing the correct steps inside the platform is just as important as spotting scams, which is why understanding how to withdraw money from PayPal safely can help you avoid mistakes triggered by phishing or fake invoices. Report any suspicious activity to both PayPal and Docusign.

How PayPal Protects Users From Scams As Attacks Evolve

PayPal employs a combination of manual investigations and advanced technologies to protect users. They limit scam accounts and decline risky transactions. PayPal's evolving fraud detection tools include reminders for customers about suspicious invoices and payment requests. Customers should:

  • Avoid calling phone numbers or clicking links in suspicious messages.

  • Change their account password and contact PayPal if they suspect phishing.

  • Enable two-factor authentication or use a Passkey.

  • Report suspicious messages directly to email providers.

  • Contact law enforcement to report scams.

For more information about invoice and money request scams, visit the PayPal US security page.

image of an invoice containing an alarmist note

Image courtesy of PayPal

image of a scam email containing an alarmist note

Image courtesy of PayPal

Cybersecurity Marketing Solutions

In response to the constantly evolving threats in the digital landscape, GrackerAI offers AI-powered cybersecurity marketing solutions. Our platform helps organizations transform security news into strategic content opportunities. By automating insight generation from industry developments, GrackerAI positions itself as a powerful tool for creating timely, relevant marketing materials that resonate with cybersecurity professionals and decision-makers. To explore our services or contact us, visit GrackerAI.

Latest Cybersecurity Trends & Breaking News

Amazon and Microsoft Battle for Quantum Computing Supremacy Amidst Industry Challenges AI Arms Race and Malware Development

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 

Deepak Gupta is a technology leader with deep experience in enterprise software, identity systems, and security-focused platform architecture. Having led CIAM and authentication products at a senior level, he brings strong expertise in building scalable, secure, and developer-ready systems. At Gracker, his work focuses on applying AI to simplify complex technical workflows while maintaining the accuracy, reliability, and trust required in cybersecurity and B2B environments.

Related Articles

How to Optimize for Google AI Overviews (Complete 2026 Guide)
optimize content for google ai overviews

How to Optimize for Google AI Overviews (Complete 2026 Guide)

Stop chasing clicks and start winning citations. Learn how to optimize for Google AI Overviews and master Generative Engine Optimization (GEO) in 2026.

By Ankit Agarwal March 31, 2026 6 min read
common.read_full_article
Perplexity Rank Tracking: Tools to Monitor Your Visibility
perplexity seo

Perplexity Rank Tracking: Tools to Monitor Your Visibility

Stop chasing Google rankings. Learn how to track your 'Citation Share' in Perplexity and discover the best tools to monitor your brand's AI search visibility.

By Ankit Agarwal March 30, 2026 6 min read
common.read_full_article
How Shopify Stores Get Cited by AI Tools Without Spending More
Shopify AI SEO

How Shopify Stores Get Cited by AI Tools Without Spending More

Learn how Shopify stores get cited by AI tools without increasing spend using smart SEO, structured data, and content optimization strategies.

By Abhimanyu Singh March 30, 2026 5 min read
common.read_full_article
How AI Uses Real-World Data to Improve Content Relevance and Search Visibility
AI SEO strategy, real world data SEO, search intent optimization, AI content optimization, SEO content strategy

How AI Uses Real-World Data to Improve Content Relevance and Search Visibility

Learn how AI uses real-world data to improve content relevance, match search intent, and boost search visibility with smarter SEO strategies.

By Mohit Singh Gogawat March 28, 2026 7 min read
common.read_full_article