Phucking Phishers
cyberstuffI work in Cybersecurity and see crap like this all the time. So I thought I should share this fairly well-crafted spam/phishing email, how to spot that it's a fake, and what to do if/when you get one.
As you see below, it looks like a legitimate PayPal request for money from some "vendor". It looks like it's coming from a legit sender (they even have the cute little blue checkmark). All the logos look legit, etc.

However, there are a few red flags (from top-to-bottom):
- They sent it TO a "donotreply" email address; usually things will be sent FROM a "donotreply" address (because emails from companies are usually unmonitored). The TO *should* be my email address.
- The greeting, "hello, donotreply@...", follows the same mistake as above.
- If you've used PayPal much at all (I use it at least once per month) the headline would sound odd to you. PayPal doesn't use the verbiage "A small reminder from...". They either send a receipt or "Reminder: ...". This is a small thing, but many small things add up to a large thing.
- The "Note from CayMay Press" section should be a note from the vendor. Instead this looks like directions from PayPal on what to do with this message.
- Also, PayPal won't ever automatically proceed with the transaction unless you contact them; they will have either already proceeded with the transaction, or it will be something you previously authorized.
- The telephone number to reach PayPal is a Hawaii area code (808); I guess the phishers thought it was close enough to a toll-free number (800, 833, 844, 855, etc.) that people won't notice?
Second half of "PayPal" spam URL of "Pay Now" button in spam
- NEVER click the link in the email. Ever. Never ever. Did I mention NEVER?
- Also, NEVER open an attachment in an email. Ever. Never ever.
- Open a new browser window and visit the website. If this is a legitimate request, you will also have the request there.
- If you're *still* not sure, contact the help through the website, not offered in the email.
- Delete the email (and/or report as spam if your email platform allows it). Don't engage with the email directly at all.
Be vigilant! Listen to your intuition. If something doesn't seem right, it probably isn't. When in doubt, reach out to the help link on the website, not in the email.