Free tools Windows power users keep installed
One-click scans. No signup required.
Yes. A genuine-looking PayPal payment request can still be malicious: in an attack documented by Fortinet, signing in through PayPal’s real page could link a victim’s account to an attacker-controlled address. A valid sender and real PayPal URL do not establish that an unsolicited request is safe.
Can a real PayPal email be a phishing scam?
Yes. The attack Fortinet described in its January 8, 2025, report, “Phish-free PayPal Phishing,” did not depend on a fake PayPal website or a forged PayPal sender. It used a genuine PayPal payment-request notification and PayPal’s real login workflow. The message could look authentic because it was produced through a legitimate service, even though the request was being used to target recipients.
This distinction matters: email checks can indicate that a message came through an authorized sending path, but they cannot tell you whether you expected the payment request or whether its destination is safe. Treat an unexpected request cautiously even if the sender address and URL look right.
How could signing in put an account at risk?
Fortinet’s documented attack relied on how a PayPal payment request could associate an account with the address receiving the request. The attacker arranged for that destination to be an address under the attacker’s control. When a recipient signed in from the request, PayPal linked the recipient’s account to that destination address, enabling the attacker to take control.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- The attacker registered a Microsoft 365 test domain and created a distribution list containing intended victims’ addresses.
- The attacker used PayPal’s web portal to request money and set that distribution list as the destination.
- The payment request arrived as a real PayPal notification. A recipient who signed in through it could trigger the account-linking behavior described above.
This is the sequence Fortinet reported; it should not be read as proof that every PayPal request or every login has this outcome. The practical warning is narrower: an unexpected request can exploit a real service workflow, so do not use the email link as your way to investigate it.
Why didn’t SPF, DKIM, or DMARC stop it?
SPF, DKIM, and DMARC help receiving systems assess whether a message is authorized or authenticated in relation to its sending domain. They are not tests of whether the recipient expected a payment request or whether the request’s destination is trustworthy.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
In Fortinet’s account, Microsoft 365’s Sender Rewrite Scheme (SRS) rewrote the sender as part of delivery from the distribution list. That behavior could help the message pass SPF, DKIM, and DMARC checks. The message also used PayPal’s valid notification and login flow rather than imitating the brand with a counterfeit site.
Oasis Security’s head of research, Elad Luz, noted that mailbox providers can have difficulty distinguishing a message sent from a verified source with the same template as a legitimate payment request. Authentication therefore addresses message provenance, not the user’s intent or the safety of the payment destination.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to check an unexpected PayPal request safely
- Do not follow the email’s link. A genuine URL is not enough to make an unsolicited request safe.
- Open PayPal directly. Use the official PayPal site or app you normally use, rather than a link in the message.
- Inspect your account activity there. Check whether the request appears in your account and whether it is one you recognize.
- Verify out of band. If you think the request might be legitimate, contact the supposed requester through a contact method you already trust, not contact details supplied in the email.
- Contact PayPal through its official support path if the request remains unexplained or you are concerned about your account.
Which defenses help, and where do they act?
No single control in the documented case answered every question. The useful distinction is whether a measure checks technical message authenticity, flags the delivery pattern, helps a person assess intent, or addresses abuse of PayPal’s workflow.
| Control | What it can address | Who it helps | When it acts |
|---|---|---|---|
| SPF, DKIM, and DMARC checks | Message authentication; they do not establish whether a request is expected or safe. | Mailbox providers and organizations handling email | During delivery or filtering |
| Staff training to question unsolicited requests | User intent, including cases where sender and URL checks appear clean | Organizations and their employees | Before a user signs in or acts on the request |
| DLP detection for distribution-list indicators | Patterns Fortinet says can indicate that a message was sent through a distribution list | Organizations with relevant email-security controls | At message handling or delivery, depending on configuration |
| PayPal-side workflow safeguards | Abuse of the account-linking behavior described in the incident | PayPal users | At the service-workflow level |
| Direct account review and official support | Whether the request appears in the user’s account and what to do about a concern | Individual account holders | After receiving the message, before responding through it |
For business email teams, Fortinet recommends training a “human firewall” and says a DLP rule can identify multiple conditions associated with messages sent through a distribution list. Those checks can complement authentication; they do not replace a person’s decision about whether a request was expected. Oasis Security’s analysis also identifies PayPal as a key party able to mitigate abuse of the underlying workflow.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




