PayPal Scam Alert: New Invoice Scheme Bypasses Email Security

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 
March 10, 2025 3 min read

PayPal Scam Warning—Dangerous Invoice Bypasses Email Security

Beware of a new PayPal invoice scam that uses old tricks to bypass email security. As Google rolls out AI-powered protections to aid Android users, scammers are reverting to methods that exploit email vulnerabilities. “PayPal scammers are using an old Docusign trick to enhance the trustworthiness of their phishing emails,” said Pieter Arntz, a malware intelligence researcher at Malwarebytes. Scammers set up Docusign accounts and use its templates to create seemingly legitimate invoices from PayPal. These documents come from Docusign, allowing them to slip past email security filters, making them particularly dangerous. Docusign investigates and closes suspicious accounts within 24 hours of detection. PayPal emphasizes its commitment to security, urging customers to remain vigilant and visit PayPal.com for safety tips.

PayPal Attack Red Flags To Watch For

A recent Malwarebytes report highlights several red flags in this scam campaign. Emails may appear to be from Docusign but could originate from fake Gmail addresses. “If it seems weird that Docusign has been used to send a document that doesn’t require a signature, it’s a red flag,” Arntz noted. Jamie Beckland, chief product officer at APIContext, warns that this Docusign scam uses APIs to bypass email security and steal login credentials. “All API owners should monitor APIs for suspicious behavior,” Beckland advises.

Mitigating The PayPal Docusign Attack

To mitigate the risk, if you receive a suspicious email claiming to be from Docusign, verify its authenticity directly on Docusign.com by clicking the Access Documents link. Enter the document security code provided in the email. If you receive an error, the document may be fraudulent. Always check your PayPal account directly, not via links in emails, for any unauthorized transactions. Report any suspicious activity to both PayPal and Docusign.

How PayPal Protects Users From Scams As Attacks Evolve

PayPal employs a combination of manual investigations and advanced technologies to protect users. They limit scam accounts and decline risky transactions. PayPal's evolving fraud detection tools include reminders for customers about suspicious invoices and payment requests. Customers should:

  • Avoid calling phone numbers or clicking links in suspicious messages.
  • Change their account password and contact PayPal if they suspect phishing.
  • Enable two-factor authentication or use a Passkey.
  • Report suspicious messages directly to email providers.
  • Contact law enforcement to report scams.

For more information about invoice and money request scams, visit the PayPal US security page. image of an invoice containing an alarmist note Image courtesy of PayPal image of a scam email containing an alarmist note Image courtesy of PayPal

Cybersecurity Marketing Solutions

In response to the constantly evolving threats in the digital landscape, GrackerAI offers AI-powered cybersecurity marketing solutions. Our platform helps organizations transform security news into strategic content opportunities. By automating insight generation from industry developments, GrackerAI positions itself as a powerful tool for creating timely, relevant marketing materials that resonate with cybersecurity professionals and decision-makers. To explore our services or contact us, visit GrackerAI.

Latest Cybersecurity Trends & Breaking News

Amazon and Microsoft Battle for Quantum Computing Supremacy Amidst Industry Challenges AI Arms Race and Malware Development

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 

Cybersecurity veteran and serial entrepreneur who built GrackerAI to solve the link between B2B SaaS product and search engine. Leads the mission to help cybersecurity brands dominate search results through AI-powered product-led ecosystem.

Related Articles

AI marketing automation

Future-Proofing Cybersecurity Marketing with AI and Automation

Streamline lead generation and campaign management using the latest AI marketing automation solutions for smarter, faster, and more accurate results.

By Ankit Agarwal October 25, 2025 5 min read
Read full article
AI tools for cybersecurity marketing

How AI Tools Like MyAIWriter Help Cybersecurity Teams Create GTM Content Faster

Discover how AI tools like MyAIWriter help cybersecurity teams create GTM content faster, improving accuracy, tone, and speed.

By Nikita Shekhawat October 25, 2025 6 min read
Read full article
growth hacking

8 Key Principles of Growth Hacking for Social Media and SEO

Unlock 8 growth hacking principles for B2B SaaS, focusing on social media & SEO. Drive cybersecurity growth with proven tactics.

By Abhimanyu Singh October 24, 2025 13 min read
Read full article

Navigating the Cybersecurity SaaS Marketing Landscape: Essential Questions for Value-Driven Strategies

Drive value with your cybersecurity SaaS marketing! Learn essential questions to shape winning strategies and achieve growth.

By Deepak Gupta October 23, 2025 9 min read
Read full article