<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Email FAIL Blog &#187; PayPal</title>
	<atom:link href="http://www.emailfail.com/tag/paypal/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.emailfail.com</link>
	<description>Stories of Email Overload, Email Hell, and Email FAIL in Action</description>
	<lastBuildDate>Wed, 31 Mar 2010 16:44:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Real Phishing Attack, or PayPal Auto Response?</title>
		<link>http://www.emailfail.com/real-phishing-attack-or-paypal-auto-response/</link>
		<comments>http://www.emailfail.com/real-phishing-attack-or-paypal-auto-response/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 16:21:17 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[PayPal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.emailfail.com/?p=1512</guid>
		<description><![CDATA[Can PayPal tell the difference between emails it sends out and phishing emails from scammers trying to trick users into providing sensitive information? Looks like the answer is no. Blogger Randy Abrams works for an online security company. His ESET Threat Blog is filled with information about how to avoid hacking, malware, and other such [...]]]></description>
			<content:encoded><![CDATA[<p></p><p style="text-align: left;">Can PayPal tell the difference between emails it sends out and phishing emails from scammers trying to trick users into providing sensitive information?</p>
<p style="text-align: left;">Looks like the answer is no.</p>
<p style="text-align: left;">
<div class="wp-caption aligncenter" style="width: 332px">
	<a href="http://www.flickr.com/photos/hitchster/3627047656"><img src="http://farm4.static.flickr.com/3306/3627047656_39c44c36bf.jpg" alt="http://www.flickr.com/photos/hitchster/ / CC BY 2.0" width="332" height="500" /></a>
	<p class="wp-caption-text">http://www.flickr.com/photos/hitchster/ / CC BY 2.0</p>
</div>
<p>Blogger Randy Abrams works for an online security company. His <a href="http://www.eset.com/threat-center/blog/" target="_blank">ESET Threat Blog</a> is filled with information about how to avoid hacking, malware, and other such computer security threats. It&#8217;s obviously a subject he knows a lot about.</p>
<p style="text-align: left;">So when he received a legitimate email from PayPal that contained a link to the PayPal login page, he wrote to them. His point was that people in his industry have been warning email users to be wary of emails containing links to banks and other financial institution&#8217;s home pages. The landing pages are often spoofed to look like the real site, and when users log in, the scammers have their personal information. So he wanted PayPal to know that it was a bad idea to include the link in their email, because it could be confusing an already confused population.</p>
<p style="text-align: left;">PayPal wrote back, in part:</p>
<blockquote style="text-align: left;"><p>Hello Randy Abrams,</p>
<p>Thanks for forwarding that suspicious-looking email. You&#8217;re right – it was a phishing attempt, and we&#8217;re working on stopping the fraud. By reporting the problem, you&#8217;ve made a difference!</p></blockquote>
<p style="text-align: left;">There are only a few explanations for how PayPal decided its own email was phishing.</p>
<ol style="text-align: left;">
<li>It was an automated response, and Randy could have emailed anything to the address he used and gotten the same response.</li>
<li>A harried employee sent the wrong email template.</li>
<li>PayPal staff can&#8217;t tell their own emails from scams.</li>
</ol>
<p style="text-align: left;">I&#8217;m betting on #1.</p>
<p style="text-align: left;">But #3 would be funnier.</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;partner=sociable" title="Print"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;bodytext=Can%20PayPal%20tell%20the%20difference%20between%20emails%20it%20sends%20out%20and%20phishing%20emails%20from%20scammers%20trying%20to%20trick%20users%20into%20providing%20sensitive%20information%3F%0D%0ALooks%20like%20the%20answer%20is%20no.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ABlogger%20Randy%20Abrams%20works%20for%20an%20online%20security%20compan" title="Digg"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;notes=Can%20PayPal%20tell%20the%20difference%20between%20emails%20it%20sends%20out%20and%20phishing%20emails%20from%20scammers%20trying%20to%20trick%20users%20into%20providing%20sensitive%20information%3F%0D%0ALooks%20like%20the%20answer%20is%20no.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ABlogger%20Randy%20Abrams%20works%20for%20an%20online%20security%20compan" title="del.icio.us"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;t=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20" title="Facebook"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="mailto:?subject=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;body=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F" title="email"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.friendfeed.com/share?title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20&amp;link=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F" title="FriendFeed"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F&amp;title=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20" title="StumbleUpon"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Real%20Phishing%20Attack%2C%20or%20PayPal%20Auto%20Response%3F%20%20-%20http%3A%2F%2Fwww.emailfail.com%2Freal-phishing-attack-or-paypal-auto-response%2F" title="Twitter"><img src="http://www.emailfail.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.emailfail.com/real-phishing-attack-or-paypal-auto-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
