Yes, it is true that Elon Musk at one time was a major shareholder in Paypal which has now, according to McAfee Labs, experienced a 600% increase in cyber attacks since the beginning of 2025.
The popular payment system appears to be back in the spotlight, with cyber crooks trying to use the platform to scam people.
One cannot help but wonder if the renewed ‘popularity’ in attacks on Paypal MAY have something to do with the fact that Musk was a major shareholder (unitil 2000) and that Paypal is now seen as fair game for attacks along the lines of Tesla bashing?
Most scams arrive as worrying emails that suggest accounts have been suspended, with users urged to update their details to get things reinstated. Other attacks include fake PayPal gift card offers, fraudulent invoices and customer support scams about billing issues.
The hallmarks of a phishing / attack expedition are all in the emails – demanding your urgent attention to a certain action in order to avoid losing access to your account.
The recent surge has been traced to a single, highly effective campaign where attackers send official-looking emails with ‘action required’ warnings, demanding users update their account details within 48 hours or face account suspension.
McAfee says it is now vital users take care when opening messages claiming to be from PayPal and watch out for links to websites that are not official PayPal domains.
PayPal Security Alerts: What to Expect
How PayPal Typically Communicates Security Issues:
- Direct Email: If your account is compromised or at risk, you’ll likely receive an email directly from PayPal. These emails are usually personalized and contain specific details about the potential threat. They will never ask for your password or other sensitive information via email.
- Account Notifications: Within your PayPal account, you’ll see notifications about any suspicious activity or security updates that affect your account.
- Security Center: The PayPal Security Center provides important information about security practices and steps you can take to protect your account.
- Website Announcements: For broader security updates or policy changes, PayPal may post announcements on its website.
What to Watch Out For:
- Suspicious Emails: Be wary of emails that claim to be from PayPal but ask for your password, credit card information, or other sensitive details. Always log in to your account directly through the official PayPal website to verify any information.
- Phishing Attempts: Scammers often try to trick users into revealing their login credentials through fake websites or emails that look like they’re from PayPal. Always double-check the website address before entering any information.
- Unusual Account Activity: Regularly monitor your account for any unfamiliar transactions or login attempts. Report any suspicious activity immediately to PayPal.
If you’re concerned about a potential security threat, it’s always best to:
- Contact PayPal directly through their official website or customer support channels.
- Change your password and enable two-factor authentication.
- Review your account activity for any suspicious transactions.
How to protect yourself from PayPal scam attempts:
- Verify all communications directly with PayPal: Never click links in emails or texts claiming to be from PayPal. Instead, open a new browser window and log in directly at Pay, Send and Save Money with PayPal, or use the official PayPal app to check for notifications.
- Scrutinise web addresses and email senders: Legitimate PayPal emails will come from addresses ending in @?paypal.com. Be wary of similar-looking domains like paypal-account.me or service-ppal.com.
- Never call phone numbers provided in suspicious messages: If you need to contact PayPal support, use only the official contact methods listed on their website: PayPal Contact Us | PayPal US
- If an email says it’s from services@paypal.com, proceed with vigilance: Some scammers spoof email addresses or use real PayPal tools like their invoices to fool you.
- Check your PayPal account regularly: Frequent monitoring allows you to spot unauthorised activity quickly and report it before significant damage occurs.
- Be sceptical of urgency and threats: Legitimate companies do not typically threaten immediate account closure or demand urgent action within short timeframes like 28 hours.
- Use PayPal’s built-in security features: Familiarise yourself with PayPal’s security centre and take advantage of their fraud protection tools.
- Report suspicious activity immediately: If you receive a suspicious message or notice unauthorised activity, report it to PayPal and change your password right away.
- Turn on two-factor authentication: If you do so, if someone gets your password, they still can’t access your account without a code sent to your phone or an authenticator.
- Skip messages that offer gift cards or say you’ll get paid for filling out a survey: PayPal doesn’t typically send these, but scammers often do.
What is Fraud? “Fraud” is any activity that relies on deception in order to achieve a gain. Fraud becomes a crime when it is a “knowing misrepresentation of the truth or concealment of a material fact to induce another to act to his or her detriment” (Black’s Law Dictionary). In other words, if you lie in order to deprive a person or organization of their money or property, you’re committing fraud.
