Researchers identify a phishing attack impersonating PayPal that allowed criminals to access peoples credentials, their PayPal account, and then their finances. Abnormal Security detected a new campaign targeting PayPal clients with a simple message that informed them their account was limited or flagged. Once they clicked the link, they were redirected to a fake PayPal website, where attackers would trick them into entering their credentials. PayPal can also link to credit cards and other types of information, with no other security measure in place, such as multi-factor authentication.”]

