What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Yes, a PayPal email can look technically authentic and still be a scam. A campaign reported on January 9, 2025 (updated January 24) used what appeared to be a genuine PayPal payment request, a real PayPal destination and Microsoft 365 infrastructure. The danger was the request and the social engineering—not necessarily a fake PayPal domain. The report does not establish a PayPal breach, a specific victim count or an active August 2026 campaign.
The safest rule is simple: do not use the email to verify itself. Open PayPal independently, check the account activity and notifications, and report anything unexpected.
What the reported PayPal phishing campaign did
According to the January 2025 report from Candid Technology, recipients received a payment request carrying PayPal branding and a legitimate-looking sender identity. The message included a genuine PayPal link or led to a real PayPal login page. The reported sequence allegedly involved an attacker-controlled PayPal recipient and a Microsoft 365 distribution-list element, including an onmicrosoft.com address.
A recipient could therefore follow a normal-looking payment flow, sign in, and disclose a password or authorize an unwanted transaction. The technical explanation involving Microsoft’s Sender Rewrite Scheme and distribution-list delivery is a reported finding attributed to Fortinet; the underlying Fortinet research was not independently available for verification here.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
This distinction matters: the available reporting describes abuse of legitimate payment-request and email infrastructure. It does not prove that PayPal’s platform was hacked or that PayPal itself initiated the fraudulent request.
Why authentication checks cannot prove a payment is legitimate
Email security mechanisms answer a narrow question: whether a message was transmitted through infrastructure authorized for a domain or service. They do not decide whether the request inside the message is honest.
| Check | What it can indicate | What it cannot prove |
|---|---|---|
| SPF | The sending server was authorized for the envelope domain. | That the payment request is genuine or that the account was not abused. |
| DKIM | The message carried a valid cryptographic signature from a domain. | That the signed content is a legitimate transaction. |
| DMARC | Alignment between visible sender identity and authentication results. | That the sender’s business request, invoice or account activity is trustworthy. |
| PayPal link | The destination may be an actual PayPal site or workflow. | That the payment request, recipient or note is legitimate. |
A criminal can abuse a real service, a compromised account or a legitimate forwarding mechanism. That is why a message can pass SPF, DKIM or DMARC and still be malicious in purpose. Conversely, Microsoft notes that an authentication failure is a warning rather than conclusive proof of fraud; not every unauthenticated message is malicious, although it deserves caution.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Red flags that still matter
- An unexpected invoice, money request, refund, account limitation or security alert.
- An unfamiliar recipient, business name, invoice description, note or distribution-list address.
- A request sent to an email address you do not use with PayPal. This is suggestive, not conclusive, if you maintain several addresses.
- Pressure to act immediately or instructions to call a number in the message.
- Requests for a password, one-time code, card number, bank details, Social Security number or identity documents.
- Attachments or prompts to download software.
- PayPal branding that does not match anything in your PayPal Activity or Notifications.
PayPal warns that suspicious messages often use alarmist language. Sellers should also verify that a payment appears in PayPal before shipping; an email claiming that a buyer paid is not proof that funds were received. See PayPal’s guidance on fake emails and payment verification and common scams.
How to verify a PayPal request safely
- Do not click the email’s links, call its phone number or open its attachment.
- Open a new browser tab and type PayPal’s address yourself, use a saved bookmark, or open the official PayPal app.
- Sign in and check Notifications, Activity, Invoices, Money requests and Automatic payments.
- Review the recipient, amount, note and reason for any matching request. An item appearing inside PayPal confirms that a request exists, not that it is honest.
- Check linked cards and bank accounts for unfamiliar activity or changes.
- If the request is plausible but unexpected, contact the supposed sender through a phone number or website you already know—not contact details in the email.
PayPal says legitimate account notifications can be checked by logging in directly. Its phishing and spoofing guidance explains this independent-login approach.
What to do if you only opened the email
If you opened the message but did not click, reply, call, download anything, sign in or disclose information, close it and avoid further interaction. Check PayPal through the official app or site, forward the complete message to PayPal, and then delete it. Opening alone is generally less serious than entering credentials, but it is not a guarantee of zero risk because messages can contain tracking or exploit attempts.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
For U.S. accounts, PayPal instructs users to forward the entire suspicious email to [email protected] without changing the subject line, then delete it: PayPal’s reporting instructions. Reporting addresses vary by country; Canadian users are directed to [email protected] under PayPal Canada’s instructions.
What to do after clicking or entering information
Act in this order if you entered a PayPal password, one-time code or payment information, or approved a transaction.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →- Stop using the suspicious page. Open PayPal independently through the app or a manually entered address.
- Change your PayPal password immediately. Change it anywhere else you reused it, especially email, banking and shopping accounts.
- Enable multifactor authentication available on the account. A phishing-resistant method is preferable where supported.
- Review recent Activity, automatic payments, linked cards and bank accounts, addresses, phone numbers, email addresses and account permissions.
- Use PayPal’s Security Center and official Help or Resolution Center paths to report unauthorized activity.
- Contact the card issuer or bank if card or bank details were exposed, or if an unauthorized transfer appears. PayPal recovery does not replace those institutions’ procedures.
- If you downloaded a file or software, update the browser and operating system, run reputable security scans and avoid using the device for sensitive logins until it is checked.
- Preserve the original email and headers for reporting if your mail system allows it; do not rely only on a screenshot.
These steps address different risks: credential exposure can threaten other accounts, unauthorized PayPal activity requires PayPal reporting, and exposed card or bank information requires the financial institution’s response.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to report the message in Microsoft 365 or Outlook
In Microsoft 365 or Outlook, select the message and choose Report → Report phishing. Microsoft’s instructions are at Protect yourself from phishing. If you use another mail client, Microsoft recommends submitting the original message as an attachment to [email protected] rather than simply forwarding it. You can also consult Microsoft’s Outlook phishing guidance.
What businesses and administrators should change
The reported use of a distribution list is especially relevant to organizations: one malicious request can reach many employees while appearing to come through familiar infrastructure. That implication follows from the reported attack description; it is not evidence of a measured campaign scale.
Strengthen technical controls
- Inspect full authentication results and message headers rather than relying on the visible From line.
- Monitor Microsoft 365 forwarding, transport rules, distribution lists and newly created or external tenant domains.
- Apply anti-phishing, impersonation-protection and external-sender policies.
- Use mailbox detections for payment-request language, callback numbers and urgent account warnings.
- Provide a reporting workflow that preserves the original message and headers.
Strengthen payment processes
- Require independent verification for invoices, refunds, wire transfers, supplier changes and requests to alter payment details.
- Train staff that SPF, DKIM, DMARC, logos and sender badges establish neither economic legitimacy nor authorization.
- Use phishing-resistant multifactor authentication where practical.
- After an incident, review PayPal business-account roles, linked funding sources, automatic payments and API credentials.
Microsoft Defender for Office 365 and its anti-phishing controls are described at Microsoft’s email-security page and Microsoft Learn. They reduce risk but cannot determine whether a legitimate PayPal request makes business sense; human approval controls remain necessary.
Recommended Free Tools
What this incident does—and does not—prove
- It demonstrates that legitimate-looking PayPal workflows and infrastructure can be used for social engineering.
- It does not establish that PayPal suffered a platform breach.
- It does not establish victim numbers, losses, campaign duration, geographic scope or widespread account takeover.
- It is a January 2025 report, not confirmation of a new August 2026 campaign.
- A real PayPal email or a request visible in PayPal can still require independent verification.
The Bottom Line
Never treat a PayPal logo, sender address, authentication result or real PayPal link as proof that a payment request is legitimate. Do not click; log in independently, check Activity and Notifications, report the original message, and promptly change exposed passwords and contact PayPal or your bank when necessary.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




