PayPal Scam Alert: New Invoice Scheme Bypasses Email Security

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 
March 10, 2025 3 min read

PayPal Scam Warning—Dangerous Invoice Bypasses Email Security

Beware of a new PayPal invoice scam that uses old tricks to bypass email security. As Google rolls out AI-powered protections to aid Android users, scammers are reverting to methods that exploit email vulnerabilities. “PayPal scammers are using an old Docusign trick to enhance the trustworthiness of their phishing emails,” said Pieter Arntz, a malware intelligence researcher at Malwarebytes. Scammers set up Docusign accounts and use its templates to create seemingly legitimate invoices from PayPal. These documents come from Docusign, allowing them to slip past email security filters, making them particularly dangerous. Docusign investigates and closes suspicious accounts within 24 hours of detection. PayPal emphasizes its commitment to security, urging customers to remain vigilant and visit PayPal.com for safety tips.

PayPal Attack Red Flags To Watch For

A recent Malwarebytes report highlights several red flags in this scam campaign. Emails may appear to be from Docusign but could originate from fake Gmail addresses. “If it seems weird that Docusign has been used to send a document that doesn’t require a signature, it’s a red flag,” Arntz noted. Jamie Beckland, chief product officer at APIContext, warns that this Docusign scam uses APIs to bypass email security and steal login credentials. “All API owners should monitor APIs for suspicious behavior,” Beckland advises.

Mitigating The PayPal Docusign Attack

To mitigate the risk, if you receive a suspicious email claiming to be from Docusign, verify its authenticity directly on Docusign.com by clicking the Access Documents link. Enter the document security code provided in the email. If you receive an error, the document may be fraudulent. Always check your PayPal account directly, not via links in emails, for any unauthorized transactions. Report any suspicious activity to both PayPal and Docusign.

How PayPal Protects Users From Scams As Attacks Evolve

PayPal employs a combination of manual investigations and advanced technologies to protect users. They limit scam accounts and decline risky transactions. PayPal's evolving fraud detection tools include reminders for customers about suspicious invoices and payment requests. Customers should:

  • Avoid calling phone numbers or clicking links in suspicious messages.
  • Change their account password and contact PayPal if they suspect phishing.
  • Enable two-factor authentication or use a Passkey.
  • Report suspicious messages directly to email providers.
  • Contact law enforcement to report scams.

For more information about invoice and money request scams, visit the PayPal US security page. image of an invoice containing an alarmist note Image courtesy of PayPal image of a scam email containing an alarmist note Image courtesy of PayPal

Cybersecurity Marketing Solutions

In response to the constantly evolving threats in the digital landscape, GrackerAI offers AI-powered cybersecurity marketing solutions. Our platform helps organizations transform security news into strategic content opportunities. By automating insight generation from industry developments, GrackerAI positions itself as a powerful tool for creating timely, relevant marketing materials that resonate with cybersecurity professionals and decision-makers. To explore our services or contact us, visit GrackerAI.

Latest Cybersecurity Trends & Breaking News

Amazon and Microsoft Battle for Quantum Computing Supremacy Amidst Industry Challenges AI Arms Race and Malware Development

Deepak Gupta
Deepak Gupta

Co-founder/CEO

 

Cybersecurity veteran and serial entrepreneur who built GrackerAI to solve the link between B2B SaaS product and search engine. Leads the mission to help cybersecurity brands dominate search results through AI-powered product-led ecosystem.

Related Articles

The Question Hub Strategy: How B2B SaaS Companies Capture AI Search Traffic

Learn how B2B SaaS companies use Question Hub strategy to capture ChatGPT, Claude & Perplexity traffic. 5-step process with real case studies & results.

By Deepak Gupta July 23, 2025 3 min read
Read full article

Google Adds Comparison Mode for Real-Time SEO Checks

Use Google’s new Search Console comparison mode for hourly SEO audits. Perfect for SaaS & cybersecurity marketers tracking real-time changes.

By Ankit Agarwal July 18, 2025 3 min read
Read full article

2025 Programmatic SEO Playbook: AI, Real-Time Data, and Market Domination

Master 2025 programmatic SEO with AI-powered content, real-time data integration, and dynamic optimization. Includes implementation guide and competitive advantages.

By Deepak Gupta July 6, 2025 10 min read
Read full article

Quality at Scale: How AI Solves Programmatic SEO's Biggest Challenge

Discover how AI transforms thin programmatic content into high-quality pages that survive Google's 2025 updates. Includes quality metrics and implementation guide.

By Deepak Gupta July 6, 2025 13 min read
Read full article