More PayPal emails hijacked to deliver tech support scams


Scammers have found another way to get deceptive messages delivered through PayPal’s legitimate services. In December 2025, we reported that PayPal closed a loophole that let scammers send real emails with fake purchase notices.

In those cases, scammers created a PayPal subscription and then paused it, which triggered PayPal’s genuine “Your automatic payment is no longer active” notification. They also set up a fake subscriber account, likely a Google Workspace mailing list, which automatically forwarded any email it received to all other group members. Recently, ConsumerWorld org alerted us that tech support scammers have found a way to manipulate the subject line of PayPal payment notifications.

Read more…
Source: Malwarebytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

    September 25, 2026

    Technology giant Kiteworks is urging customers to shut down their systems after the company received information that hackers may attempt to target them. Kiteworks (formerly Accellion), which makes tools for transferring large files and sensitive datasets over the internet, confirmed to TechCrunch that it had notified its customers about a potential threat. The news was first ...

  • Australia: Rogue AI agents worked together for months to gain access to government health data

    September 24, 2026

    A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website. Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds ...

  • CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

    September 23, 2026

    On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending ...

  • ShinyHunters hackers say they breached FBI, stole data on bureau employees

    September 22, 2026

    The digital extortion group known as “ShinyHunters” said on Tuesday that it had breached the Federal Bureau of Investigation and stolen data on a huge number of current and former FBI employees. The bureau did not respond to repeated messages seeking comment on Tuesday. In a statement posted to its dark-web site and during an online chat ...

  • Meta Muse already has a majorly worrying zero-day security issue

    September 22, 2026

    Meta’s new Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. However, it’s not as straightforward as your usual zero-day – to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before ...

  • Unmasking EvilTokens: Getting to the root of device code phishing

    September 22, 2026

    Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets. This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 ...