Fake PayPal Emails Cost £8million In Theft

Action Fraud is warning people selling items online to be on the lookout for criminals sending fake PayPal emails. Between January 2020 and September 2020, 21,349 crime reports were made to Action Fraud about fake PayPal emails. Victims reported losing a total of £7,891,077 during this time. Those targeted included people selling jewelry, furniture and electronics via online marketplaces. 

Reports of fake PayPal emails to Action Fraud made up a third of all reports of online shopping and auction fraud during this period.

Criminals have been targeting people selling items online, by sending them emails purporting to be from PayPal. The emails trick victims into believing they have received payment for the items they’re selling on the platform. Typically, after receiving these emails, victims will then send the item to the criminal. This leaves them at a further disadvantage having not received any payment for the item and also no longer being in possession of it.

Pauline Smith, Head of Action Fraud said: 

“We know that criminals will go to great lengths to target people on online marketplaces, especially now many more people are selling items online due to the coronavirus pandemic....Criminals have taken advantage of the coronavirus outbreak to commit fraud and will continue to do so. We are working hard, together with our partners, such as PayPal, to raise awareness of the types of scams being committed and prevent people from falling victim." 

 “It’s really important to follow our advice to help protect yourself. If you receive a suspicious email claiming you’ve received payment for an item you’re selling, take five minutes to check directly with PayPal that the communication is genuine. If something feels wrong then always question it.”

Action Fraud issued a similar warning earlier this year, after it received 3,059 crime reports about fake PayPal emails between October 2019 and December 2019.

Victims reported losing a total of £1,121,446 during this time. Reports of fake PayPal emails to Action Fraud made up almost 18% of all reports of online shopping and auction fraud during this period.

In one instance, a victim received a fake email purporting to be from PayPal claiming the buyer accidently paid more than they should have.The buyer then asked the victim to pay the difference by sending a gift card to them loaded with the difference, which they did. In another case, the fake email from PayPal claimed the buyer had accidently paid for the item twice.The buyer then asked the seller to wire the overpayment to a bank account in a different country.

What Do You Need To Do?

  • Sellers beware: If you’re selling items on an online marketplace, be aware of the warning signs that your buyer is a scammer. Scammers may have negative feedback history, or may have recently set up a new account to avoid getting poor feedback. Don’t be persuaded into sending anything until you can verify you’ve received the payment.
     
  • Scam messages: Don’t click on the links or attachments in suspicious emails, and never respond to messages that ask for your personal or financial details.

If you think you’ve been a victim of fraud, report it to Action Fraud online at actionfraud.police.uk or by calling 0300 123 2040.

A spokesperson for PayPal, said:

“At PayPal we go to great lengths to protect our customers in the UK, but there are still a few simple precautions we should all take to avoid falling victim to scams... All communications from PayPal to account holders would be sent to the secure message centre within their PayPal account. You will have a secure message waiting if PayPal does need you to take any action... A genuine PayPal email will only ever address you by your full name, anything that starts differently should immediately raise your suspicions. Look out for spelling mistakes, which are a common tell-tale sign of a fraudulent message.”

If you think that you’ve received a suspicious email, you can forward it to PayPal, without changing the subject line. PayPal will let you know whether it is fraudulent or not

PayPal:       Action Fraud:          Gedling Eye:     South Wales Argus:       Birmingham Mail:   

You Might Also Read:

Online Shoppers Have Lost Over £16m To Lockdown Fraud:

 

« British National Cyber Security Guidance
Cyber Security For Home Working »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Booz Allen Hamilton

Booz Allen Hamilton

Booz Allen Hamilton is a management & tech consulting firm. Technology services include cloud computing, cyber security, systems development and integration.

Security Current

Security Current

Security Current's proprietary content and events provide insight, actionable advice and analysis giving executives the latest information to make knowledgeable decisions.

Micro Focus

Micro Focus

Micro Focus is one of the world’s largest enterprise software providers. We deliver trusted and proven mission-critical software that keeps the digital world running.

Quadible

Quadible

Quadible BehavAuth is an AI-platform that continuously authenticates the users, without the need of any input, by learning their behavioural patterns.

Cyber Science

Cyber Science

Cyber Science is the flagship conference of C-MRiC, focusing on pioneering research and innovation in Cyber Situational Awareness, Social Media, Cyber Security and Cyber Incident Response.

German Israeli Partnership Accelerator (GIPA)

German Israeli Partnership Accelerator (GIPA)

GIPA is based on two pillars: it is an incubator aimed at young academics and a program to transfer cybersecurity expertise to corporate partners.

Elron Ventures

Elron Ventures

Elron partner with early stage ventures to build companies that transform lives and industries. Our main areas of focus are enterprise software, cybersecurity, and healthcare.

IntaPeople

IntaPeople

IntaPeople are IT and engineering recruitment specialists. We have specialist teams for job sectors including Cybersecurity, IT infrastructure and DevOps.

Aujus Cybersecurity

Aujus Cybersecurity

Aujas is a pure-play cyber security services company with deep expertise in Identity and Access Management, Managed Security and Security Testing services.

M2MD Technologies

M2MD Technologies

M2MD Technologies offers solutions optimized for cellular IoT that provide stronger security, reduced costs, enhanced user experience, and ultimately generates higher returns for stakeholders.

PagerDuty

PagerDuty

PagerDuty is the central nervous system for a company’s digital operations. We identify issues in real-time and bring together the right people to respond to problems faster.

Trackd

Trackd

At trackd, we’re re-imaging vulnerability remediation for the benefit of the entire cyber security community. Automating Vulnerability Remediation without the Fear of Disruption.

Allure Security

Allure Security

Allure Security AI-driven brand protection scans more of the online world for faster, more accurate detection & removal of spoof websites, social media & mobile apps -- before customers fall victim.

The Cyber Scheme

The Cyber Scheme

The Cyber Scheme provides NCSC certified and assured assessments, training and career support for security testers & technical cyber professionals.

Secure Halo

Secure Halo

Secure Halo has been protecting the intellectual assets and sensitive information of the federal government and private sector for 20+ years, through our proactive approach to risk and cybersecurity.

Clarity

Clarity

Clarity is an AI cybersecurity startup that protects against deepfakes and new social engineering and phishing attack vectors accelerated by the rapid adoption of Generative AI.