Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Blog

Fake Etsy Invoice Scam Tricks Sellers Into Sharing Credit-Card Information

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A documented phishing campaign has targeted Etsy sellers with official-looking invoice PDFs and fake Etsy verification pages designed to steal credit-card details. Malwarebytes reported the campaign on February 12, 2025. The specific domains may disappear or change, but the impersonation tactic can recur. Treat any unexpected Etsy invoice or account-verification request as suspicious until you verify it inside Etsy—not through the message’s link, attachment, QR code, phone number, or reply address.

How the fake Etsy invoice scam works

The reported sequence is built to move a seller from a plausible notice to a counterfeit payment form:

  1. The seller receives an email or Etsy-related message impersonating Etsy Support.
  2. The message includes or links to an official-looking invoice, often as a PDF.
  3. The PDF may appear to be hosted on etsystatic.com, a legitimate Etsy-associated static-content domain.
  4. It tells the seller to confirm, verify, or validate the account.
  5. A link opens an Etsy-styled but counterfeit website.
  6. The fake page requests personal information and eventually credit-card details.
  7. The submitted card information can be used for unauthorized purchases or resold.

Malwarebytes reported this flow and identified historical .cfd domains associated with the campaign. Those indicators are not a complete or current blocklist: attackers can replace domains quickly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The campaign’s central behavior, as reported, is phishing and payment-data theft. Do not assume that every PDF in the campaign contained malware. A PDF is still potentially dangerous if it launches a browser, prompts a download, or asks you to sign in.

Read Malwarebytes’ report on the campaign.

Why the invoice can look convincing

The scam combines familiar branding with pressure and a plausible business pretext:

  • Etsy logos, colors, and support-style wording make the message look official.
  • A PDF invoice feels more formal than a plainly written phishing email.
  • Hosting a document on a legitimate-looking static-content domain can increase trust.
  • Threats of account closure, suspension, or withheld payments encourage rushed decisions.
  • Generic greetings such as “Dear Seller” or “Hello Etsy Member” avoid having to know the shop owner’s name.
  • A polished counterfeit verification page makes the final card request seem routine.

A legitimate domain appearing somewhere in a message does not prove that the entire message is safe. Attackers can use legitimate hosting, redirects, compromised accounts, or copied branding. The destination you reach—and whether the request appears inside your authenticated Etsy account—matters more than the logo or PDF design.

Red flags Etsy sellers should check

  • Lookalike sender: The actual address uses a spelling variation, a different domain, or a deceptive display name. Inspect the full address rather than trusting the name shown in your inbox.
  • Generic wording: The message does not accurately identify your shop, order, or account issue.
  • Urgency: It threatens immediate suspension, closure, or loss of payments unless you act.
  • External contact: It asks you to leave Etsy, reply to another email address, call a supplied number, or continue on another service.
  • Hidden destination: It uses a QR code, shortened URL, or embedded link whose destination is unclear.
  • Deceptive domain: A URL contains “Etsy” but is not actually under etsy.com. For example, login-etsy.com is not Etsy, and [email protected] is controlled by offer.example.
  • Sensitive-data request: It asks for a full card number, CVV, Etsy password, one-time verification code, or tax identification number.
  • No matching in-account notice: You cannot find a corresponding alert in Shop Manager or an official message in Etsy’s From Etsy folder.

Etsy specifically warns that simply seeing “Etsy” in a URL is not proof that the address belongs to Etsy. See Etsy’s phishing guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to verify an Etsy message safely

  1. Do not use the message. Do not click its link, open its attachment, scan its QR code, reply, or call a number it provides.
  2. Open Etsy independently. Type the Etsy address yourself, use a known bookmark, or open the official app.
  3. Check Messages. Look in the From Etsy folder. Etsy says legitimate Etsy messages appear there and carry a From Etsy badge and Etsy staff indicator.
  4. Check Shop Manager. Look for a matching account, billing, security, or policy notice.
  5. Contact support through Etsy. Use the official Etsy Help Center contact flow, not contact details in the suspicious message.

Etsy says official emails contain /etsy.com/ in the sender address, but sender inspection should be only one check. Email addresses and display names can be spoofed, and a link can lead somewhere different from the visible text. Etsy also says it does not have a general customer-service phone number for unsolicited calls.

Does Etsy ever ask sellers to verify information?

Etsy may have legitimate seller-identity and transaction-verification processes. The safety distinction is the channel and destination: begin from Etsy directly, use Shop Manager or the official Help Center, and follow an expected authenticated workflow.

Etsy documents circumstances in which it may use SendSafely to request additional information, such as government-issued identification, for transaction confirmation. That possibility does not make an unexpected invoice PDF or external page requesting a full card number legitimate.

Etsy says card data submitted through its own payment systems is protected with TLS and tokenized through payment processors. That is different from entering card details into a page reached from an unsolicited invoice. Etsy’s safety guidance says not to provide a full credit-card number, password, or tax identification number by email, Etsy Message, or phone. See Etsy’s card-security information and safety tips.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do before clicking

  1. Do not open the attachment or follow the link.
  2. Do not reply or call the sender.
  3. Open Etsy independently and check Messages, From Etsy, Shop Manager, and account-security notices.
  4. Inspect the sender and destination domain without visiting the suspicious page.
  5. Report the message as spam.
  6. Forward a suspicious email or relevant screenshots to [email protected].
  7. Preserve the message, PDF, headers, URL, and timestamps needed for reporting, then delete it.

Etsy’s reporting paths are:

  • Etsy.com: Your account → Messages → select the message → Report.
  • Etsy app: You → Messages → select the message → Report.
  • Etsy Seller app: Messages → select the message → three-dot menu → Mark as spam.

The phishing-report address is for reporting and should not be treated as a support channel that will necessarily send a reply.

If you clicked the link

Close the page immediately. Do not enter more information, download files, or return to the site to test it.

If you entered nothing and downloaded nothing, the exposure may be limited, but remain alert for follow-up messages. If a file downloaded, the page behaved unusually, or the PDF prompted an installation, run a reputable device-security scan. Seek professional technical help if software executed, browser warnings appeared, or the device shows signs of compromise.

If you entered an Etsy password, change it immediately from Etsy.com or the official app. Change every other account that reused that password, especially the email account associated with your shop, and enable two-factor authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you entered card information

Call the card issuer first. Use the number on the back of the card or the issuer’s official app—not a number in the scam.

  1. Report the card as compromised.
  2. Ask whether the account number should be replaced.
  3. Review pending and posted transactions.
  4. Dispute unauthorized charges through the issuer.
  5. Replace the card if advised.
  6. Continue monitoring the account for unfamiliar activity.

Then report the phishing attempt to Etsy and the appropriate fraud-reporting authority in your country. Keep the email, PDF, fake URL, screenshots, and timestamps. Changing your Etsy password is important if credentials were exposed, but it cannot protect or undo exposure of a card number that was already submitted.

If you entered an Etsy password or lost account access

Treat the Etsy account as potentially compromised. Change the Etsy password, change reused passwords, enable two-factor authentication, and monitor sign-in notifications. Save your two-factor backup codes securely.

After regaining access, inspect the areas a criminal could alter:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Shop listings and prices
  • Messages sent from the account
  • Orders and refunds
  • Bank and payout details
  • Contact email and phone number
  • Security settings and active sessions

If you cannot sign in or find unauthorized changes, contact Etsy through the official account-fraud guidance and Help Center. Also secure the email account linked to Etsy: an attacker who controls that inbox may be able to reset the shop account or intercept security notices.

Historical domains associated with the reported campaign

Malwarebytes listed the following as examples associated with the February 2025 campaign. They are shown defanged to avoid creating clickable links:

com-etsy-verify[.]cfd
etsy-car[.]switchero[.]cfd
etsy[.]1562587027[.]cfd
etsy[.]3841246[.]cfd
etsy[.]39849329[.]cfd
etsy[.]447385638[.]cfd
etsy[.]57434[.]cfd
etsy[.]6562587027[.]cfd
etsy[.]checkid1573[.]cfd
etsy[.]chekup-out[.]cfd
etsy[.]coinbox[.]cfd
etsy[.]fastpay[.]cfd
etsy[.]offer584732[.]cfd
etsy[.]paylink[.]cfd
etsy[.]paymint[.]cfd
etsy[.]paywave[.]cfd
etsy[.]requlred-verlfication[.]cfd
verlflcation-etsy[.]cfd

These are historical indicators, not proof that every .cfd domain is part of this campaign and not a current guarantee that each domain remains malicious. Domains can be abandoned, repurposed, or replaced. Do not visit them to investigate.

Optional prevention layers

Browser protection such as Malwarebytes Browser Guard can be a useful preventive layer against some malicious websites, trackers, ads, and phishing domains. It cannot recover a card number after submission and does not replace card-issuer action, unique passwords, two-factor authentication, or careful verification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For most sellers, the highest-value safeguards are free or already available: use the issuer’s fraud alerts, use a password manager for unique Etsy and email passwords, enable two-factor authentication, and keep devices updated. Endpoint security is particularly relevant if a suspicious file was downloaded or executed. Identity-monitoring subscriptions are not automatically necessary when only a card number was exposed; card replacement and issuer monitoring are the immediate priorities.

Sources and official guidance

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.