Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A documented phishing campaign has targeted Etsy sellers with official-looking invoice PDFs and fake Etsy verification pages designed to steal credit-card details. Malwarebytes reported the campaign on February 12, 2025. The specific domains may disappear or change, but the impersonation tactic can recur. Treat any unexpected Etsy invoice or account-verification request as suspicious until you verify it inside Etsy—not through the message’s link, attachment, QR code, phone number, or reply address.
How the fake Etsy invoice scam works
The reported sequence is built to move a seller from a plausible notice to a counterfeit payment form:
- The seller receives an email or Etsy-related message impersonating Etsy Support.
- The message includes or links to an official-looking invoice, often as a PDF.
- The PDF may appear to be hosted on
etsystatic.com, a legitimate Etsy-associated static-content domain. - It tells the seller to confirm, verify, or validate the account.
- A link opens an Etsy-styled but counterfeit website.
- The fake page requests personal information and eventually credit-card details.
- The submitted card information can be used for unauthorized purchases or resold.
Malwarebytes reported this flow and identified historical .cfd domains associated with the campaign. Those indicators are not a complete or current blocklist: attackers can replace domains quickly.
The campaign’s central behavior, as reported, is phishing and payment-data theft. Do not assume that every PDF in the campaign contained malware. A PDF is still potentially dangerous if it launches a browser, prompts a download, or asks you to sign in.
#1 Best Overall
Read Malwarebytes’ report on the campaign.
Why the invoice can look convincing
The scam combines familiar branding with pressure and a plausible business pretext:
- Etsy logos, colors, and support-style wording make the message look official.
- A PDF invoice feels more formal than a plainly written phishing email.
- Hosting a document on a legitimate-looking static-content domain can increase trust.
- Threats of account closure, suspension, or withheld payments encourage rushed decisions.
- Generic greetings such as “Dear Seller” or “Hello Etsy Member” avoid having to know the shop owner’s name.
- A polished counterfeit verification page makes the final card request seem routine.
A legitimate domain appearing somewhere in a message does not prove that the entire message is safe. Attackers can use legitimate hosting, redirects, compromised accounts, or copied branding. The destination you reach—and whether the request appears inside your authenticated Etsy account—matters more than the logo or PDF design.
Red flags Etsy sellers should check
- Lookalike sender: The actual address uses a spelling variation, a different domain, or a deceptive display name. Inspect the full address rather than trusting the name shown in your inbox.
- Generic wording: The message does not accurately identify your shop, order, or account issue.
- Urgency: It threatens immediate suspension, closure, or loss of payments unless you act.
- External contact: It asks you to leave Etsy, reply to another email address, call a supplied number, or continue on another service.
- Hidden destination: It uses a QR code, shortened URL, or embedded link whose destination is unclear.
- Deceptive domain: A URL contains “Etsy” but is not actually under
etsy.com. For example,login-etsy.comis not Etsy, and[email protected]is controlled byoffer.example. - Sensitive-data request: It asks for a full card number, CVV, Etsy password, one-time verification code, or tax identification number.
- No matching in-account notice: You cannot find a corresponding alert in Shop Manager or an official message in Etsy’s From Etsy folder.
Etsy specifically warns that simply seeing “Etsy” in a URL is not proof that the address belongs to Etsy. See Etsy’s phishing guidance.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →How to verify an Etsy message safely
- Do not use the message. Do not click its link, open its attachment, scan its QR code, reply, or call a number it provides.
- Open Etsy independently. Type the Etsy address yourself, use a known bookmark, or open the official app.
- Check Messages. Look in the From Etsy folder. Etsy says legitimate Etsy messages appear there and carry a From Etsy badge and Etsy staff indicator.
- Check Shop Manager. Look for a matching account, billing, security, or policy notice.
- Contact support through Etsy. Use the official Etsy Help Center contact flow, not contact details in the suspicious message.
Etsy says official emails contain /etsy.com/ in the sender address, but sender inspection should be only one check. Email addresses and display names can be spoofed, and a link can lead somewhere different from the visible text. Etsy also says it does not have a general customer-service phone number for unsolicited calls.
Does Etsy ever ask sellers to verify information?
Etsy may have legitimate seller-identity and transaction-verification processes. The safety distinction is the channel and destination: begin from Etsy directly, use Shop Manager or the official Help Center, and follow an expected authenticated workflow.
Etsy documents circumstances in which it may use SendSafely to request additional information, such as government-issued identification, for transaction confirmation. That possibility does not make an unexpected invoice PDF or external page requesting a full card number legitimate.
Etsy says card data submitted through its own payment systems is protected with TLS and tokenized through payment processors. That is different from entering card details into a page reached from an unsolicited invoice. Etsy’s safety guidance says not to provide a full credit-card number, password, or tax identification number by email, Etsy Message, or phone. See Etsy’s card-security information and safety tips.
Recommended Free Tools
What to do before clicking
- Do not open the attachment or follow the link.
- Do not reply or call the sender.
- Open Etsy independently and check Messages, From Etsy, Shop Manager, and account-security notices.
- Inspect the sender and destination domain without visiting the suspicious page.
- Report the message as spam.
- Forward a suspicious email or relevant screenshots to [email protected].
- Preserve the message, PDF, headers, URL, and timestamps needed for reporting, then delete it.
Etsy’s reporting paths are:
- Etsy.com: Your account → Messages → select the message → Report.
- Etsy app: You → Messages → select the message → Report.
- Etsy Seller app: Messages → select the message → three-dot menu → Mark as spam.
The phishing-report address is for reporting and should not be treated as a support channel that will necessarily send a reply.
If you clicked the link
Close the page immediately. Do not enter more information, download files, or return to the site to test it.
If you entered nothing and downloaded nothing, the exposure may be limited, but remain alert for follow-up messages. If a file downloaded, the page behaved unusually, or the PDF prompted an installation, run a reputable device-security scan. Seek professional technical help if software executed, browser warnings appeared, or the device shows signs of compromise.
Rank #2
If you entered an Etsy password, change it immediately from Etsy.com or the official app. Change every other account that reused that password, especially the email account associated with your shop, and enable two-factor authentication.
If you entered card information
Call the card issuer first. Use the number on the back of the card or the issuer’s official app—not a number in the scam.
- Report the card as compromised.
- Ask whether the account number should be replaced.
- Review pending and posted transactions.
- Dispute unauthorized charges through the issuer.
- Replace the card if advised.
- Continue monitoring the account for unfamiliar activity.
Then report the phishing attempt to Etsy and the appropriate fraud-reporting authority in your country. Keep the email, PDF, fake URL, screenshots, and timestamps. Changing your Etsy password is important if credentials were exposed, but it cannot protect or undo exposure of a card number that was already submitted.
If you entered an Etsy password or lost account access
Treat the Etsy account as potentially compromised. Change the Etsy password, change reused passwords, enable two-factor authentication, and monitor sign-in notifications. Save your two-factor backup codes securely.
After regaining access, inspect the areas a criminal could alter:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Shop listings and prices
- Messages sent from the account
- Orders and refunds
- Bank and payout details
- Contact email and phone number
- Security settings and active sessions
If you cannot sign in or find unauthorized changes, contact Etsy through the official account-fraud guidance and Help Center. Also secure the email account linked to Etsy: an attacker who controls that inbox may be able to reset the shop account or intercept security notices.
Historical domains associated with the reported campaign
Malwarebytes listed the following as examples associated with the February 2025 campaign. They are shown defanged to avoid creating clickable links:
com-etsy-verify[.]cfd
etsy-car[.]switchero[.]cfd
etsy[.]1562587027[.]cfd
etsy[.]3841246[.]cfd
etsy[.]39849329[.]cfd
etsy[.]447385638[.]cfd
etsy[.]57434[.]cfd
etsy[.]6562587027[.]cfd
etsy[.]checkid1573[.]cfd
etsy[.]chekup-out[.]cfd
etsy[.]coinbox[.]cfd
etsy[.]fastpay[.]cfd
etsy[.]offer584732[.]cfd
etsy[.]paylink[.]cfd
etsy[.]paymint[.]cfd
etsy[.]paywave[.]cfd
etsy[.]requlred-verlfication[.]cfd
verlflcation-etsy[.]cfd
These are historical indicators, not proof that every .cfd domain is part of this campaign and not a current guarantee that each domain remains malicious. Domains can be abandoned, repurposed, or replaced. Do not visit them to investigate.
Optional prevention layers
Browser protection such as Malwarebytes Browser Guard can be a useful preventive layer against some malicious websites, trackers, ads, and phishing domains. It cannot recover a card number after submission and does not replace card-issuer action, unique passwords, two-factor authentication, or careful verification.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallFor most sellers, the highest-value safeguards are free or already available: use the issuer’s fraud alerts, use a password manager for unique Etsy and email passwords, enable two-factor authentication, and keep devices updated. Endpoint security is particularly relevant if a suspicious file was downloaded or executed. Identity-monitoring subscriptions are not automatically necessary when only a card number was exposed; card replacement and issuer monitoring are the immediate priorities.
Quick Recap
Sources and official guidance
- Malwarebytes: fake Etsy invoice scam report
- Etsy: protecting yourself from phishing scams
- Etsy: contacting support
- Etsy: making your account more secure
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

