PayPal Scam Alert: New Invoice Scheme Bypasses Email Security

Vijay Shekhawat
Vijay Shekhawat

Software Architect

 
March 10, 2025 3 min read

PayPal Scam Warning—Dangerous Invoice Bypasses Email Security

Beware of a new PayPal invoice scam that uses old tricks to bypass email security. As Google rolls out AI-powered protections to aid Android users, scammers are reverting to methods that exploit email vulnerabilities.

“PayPal scammers are using an old Docusign trick to enhance the trustworthiness of their phishing emails,” said Pieter Arntz, a malware intelligence researcher at Malwarebytes. Scammers set up Docusign accounts and use its templates to create seemingly legitimate invoices from PayPal. These documents come from Docusign, allowing them to slip past email security filters, making them particularly dangerous.

Docusign investigates and closes suspicious accounts within 24 hours of detection. PayPal emphasizes its commitment to security, urging customers to remain vigilant and visit PayPal.com for safety tips.

PayPal Attack Red Flags To Watch For

A recent Malwarebytes report highlights several red flags in this scam campaign. Emails may appear to be from Docusign but could originate from fake Gmail addresses. “If it seems weird that Docusign has been used to send a document that doesn’t require a signature, it’s a red flag,” Arntz noted.

Jamie Beckland, chief product officer at APIContext, warns that this Docusign scam uses APIs to bypass email security and steal login credentials. “All API owners should monitor APIs for suspicious behavior,” Beckland advises.

Mitigating The PayPal Docusign Attack

To mitigate the risk, if you receive a suspicious email claiming to be from Docusign, verify its authenticity directly on Docusign.com by clicking the Access Documents link. Enter the document security code provided in the email. If you receive an error, the document may be fraudulent.

Always check your PayPal account directly, not via links in emails, for any unauthorized transactions. Report any suspicious activity to both PayPal and Docusign.

How PayPal Protects Users From Scams As Attacks Evolve

PayPal employs a combination of manual investigations and advanced technologies to protect users. They limit scam accounts and decline risky transactions. PayPal's evolving fraud detection tools include reminders for customers about suspicious invoices and payment requests.

Customers should:

  • Avoid calling phone numbers or clicking links in suspicious messages.
  • Change their account password and contact PayPal if they suspect phishing.
  • Enable two-factor authentication or use a Passkey.
  • Report suspicious messages directly to email providers.
  • Contact law enforcement to report scams.

For more information about invoice and money request scams, visit the PayPal US security page.

image of an invoice containing an alarmist note
Image courtesy of PayPal

image of a scam email containing an alarmist note
Image courtesy of PayPal

Cybersecurity Marketing Solutions

In response to the constantly evolving threats in the digital landscape, GrackerAI offers AI-powered cybersecurity marketing solutions. Our platform helps organizations transform security news into strategic content opportunities. By automating insight generation from industry developments, GrackerAI positions itself as a powerful tool for creating timely, relevant marketing materials that resonate with cybersecurity professionals and decision-makers.

To explore our services or contact us, visit GrackerAI.

Vijay Shekhawat
Vijay Shekhawat

Software Architect

 

Principal architect behind GrackerAI's self-updating portal infrastructure that scales from 5K to 150K+ monthly visitors. Designs systems that automatically optimize for both traditional search engines and AI answer engines.

Related Articles

2025 Nonprofit Marketing Trends: AI Strategies & Best Practices

Social media is a powerful tool for nonprofit organizations to connect with their target audiences. The evolving landscape of these platforms necessitates staying updated on best practices for optimal engagement and impact.

By Hitesh Kumawat July 23, 2025 5 min read
Read full article

Unlocking Business Potential: The Role of Chief Content Officers

Chief content officers (CCOs) are increasingly common in non-media companies, driven by the growing demand for unbranded content that resonates with consumers. Over 50 non-media companies, including Airbnb and HP, have appointed CCOs to foster authentic connections with their audiences. These roles differ significantly from traditional marketing positions, focusing on producing credible, independent content that builds trust. Angela Matusik from HP states, “This is not about steering people directly to purchase. It’s about creating long-term relationships with consumers.”

By Govind Kumar July 23, 2025 3 min read
Read full article

Revamping Corporate Sustainability: Beyond Checkboxes to Impact

Sustainability has become essential for businesses, transitioning from a secondary consideration to a core corporate strategy. Companies that view sustainability merely as a checkbox risk falling behind in today's market. A PwC survey indicates over 80 percent of consumers are concerned about climate change. As sustainability expectations shift, leaders are urged to build innovative ecosystems and enhance product offerings.

By Abhimanyu Singh July 22, 2025 3 min read
Read full article

AI Revolutionizes Content Creation in Digital Marketing & SaaS

The rise of artificial intelligence (AI) is transforming digital marketing strategies, making content creation more efficient. AI content writers provide innovative solutions for generating engaging and informative content at scale. These advancements in technology enable businesses to reach wider audiences with personalized messaging, which enhances engagement and conversion rates.

By Ankit Lohar July 22, 2025 3 min read
Read full article