Skip to main content

Don't fall for the PayPal Invoice scam

The latest phishing scam is using PayPal to convince victims that they need to pay an invoice for hundreds if not thousands of pounds…an invoice that doesn’t really exist.

What is a phishing scam?

A phishing scam is a kind of fraud where a victim is sent an email, text or is called directly, and convinced through social engineering to disclose their bank details, account details or other personal information. Perpetrators will devise a number of different ways to convince victims to part with their details, usually using something current and relevant. 

These phishing scams are often sent out en masse; the scammers contact as many people as possible so they can get as many responses as possible. We’ve seen a number of different phishing scams claiming to be from trusted businesses, organisations and even family members. Emails can be about the covid-19 vaccine, the cost of living crisis or subscription services - but the goal is the same, to get victims to pass on their information.

What is the PayPal Invoice scam?

The PayPal invoice scam is a phishing scam that is sent over email. Victims receive an email from PayPal, with an invoice attached. The note attached to this invoice explains that you have an outstanding payment, and the money will be taken from your PayPal account today. 

The note in the invoice goes on to state that if you didn’t make this purchase, you can contact PayPal to refund this payment. It also provides you with the number to contact PayPal on. If you’ve not figured out where this is going yet, the phone number does not connect you to PayPal, and instead calls a scammer who will refund this false payment by relieving you of your PayPal details, and then emptying your account. You can see a screenshot of this email at the following link.

The pitfalls of the PayPal Invoice scam

This scam has been so effective because scammers are using PayPal's invoicing system. This means that the sender of the email is PayPal, so it looks a lot more legitimate than it is. 

This is because the fraudulent invoice is sent through PayPal’s application. As such, even when you head to your PayPal account - without clicking any links in the email - you’ll still see this fraudulent invoice. The important thing to remember is that anyone can send a PayPal invoice to anyone else, at any time. Just because it comes through PayPal’s website, it doesn’t make it legitimate. 

However, there are some indicators in the email that you’re looking at a scam. Many phishing scams fall down at their grammar and the note attached to this invoice is no exception, ‘This transaction will reflect on PayPal activity…’ just doesn’t sound right.

The most important thing to note, however, is that the PayPal information is underneath a big heading that says, ‘Seller note to customer’. That means whoever has sent this invoice has typed this message to you, including the phone number; it isn’t an official security message from PayPal.

What should you do if you receive a PayPal invoice you weren’t expecting?

Head to your PayPal account, without clicking any links in the email. PayPal states that you can, ‘Cancel any unwarranted invoices or money requests by logging in to the PayPal website or the PayPal app.’ Never try to contact PayPal through a phone number or email address you’ve received in the Seller note - it’s the scammer you’ll get through to.

Tweet us @TranscenditUK


The Transcendit Way

Transcendit understand that when you choose to work with us, whether we're taking care of your IT, app or web development, you're trusting us with part of your business. So whether we're looking after your computers, phone systems or servers we always do things 'the Transcendit way'.

The whole of our team adhere to the same values, beliefs and policies - the principles that were written when Transcendit first formed in 2000. Whether you come to us for cloud services or recovery backup you can be confident that you'll always receive the same excellent service.

The Transcendit way outlines how we do business; following the same straightforward principles with every client and customer, regardless of how big or small they may be.

That means we get to know you and your business. We offer you a friendly, professional and efficient service, and we'll always be honest with you.
We understand that not everybody speaks fluent IT, so we try to explain things in a way that is simple and clear. We always spend as much time as is necessary explaining things to you.
If you need to talk to us about something, no matter how insignificant, we are only ever a phone call away – and we’re never too busy to make you a cup of tea and have a sit down with you in person.
We understand how frustrating it can be when things are late. When we schedule an appointment with you, we are there when you’re expecting us. If something prevents us from getting there, we always call you in advance to let you know.
Sometimes things can go wrong, but we never lie to you or try to cover something up. If things go askew we tell you what’s happened and how we plan to prevent it affecting your business.
We want you to continuously benefit from working with us. We regularly discuss your business and make suggestions for improving systems and processes wherever we can – but we never try to push you into a purchase.
When we quote a fixed price, that's always the amount we charge – you won’t find any nasty surprises on a bill from us. If you are paying by time and materials, we inform you if our approximations could change.
We understand the importance of privacy for your business and your customers. We respect the confidentiality of your data, and we will never pass on your information to third parties.
We appreciate it when you take the time to give us feedback. A system called CustomerSure records our client's responses, so you can trust that our reviews are from real people.
Find out what they're saying here.
We have worked with Transcendit for many years (it must be over 10 years) and their services are second to none. I work very closely with Christophe at Transcendit for our website’s communications to stakeholders and there’s nothing he can’t do! Christophe is very professional, prompt with emails and always checks with myself if everything is how it should be. The staff at Transcendit are highly skilled and extremely knowledgeable when it comes to IT. We look forward to continuing to work with Transcendit for the next however many years Laura Driver, NRCPD

Based on 12075 reviews our customers rate us 9.8/10. Reviews and ratings by Customersure. 09-October-2024

Transcendit are proud sponsors of CHUF, the Children's Heart Unit Fund.

Transcendit is a Microsoft Gold certified partner
VMWARE partner
Vipre partner
IPCortex partner
WithSecure partner
DELL partner
Barracuda partner
Veeam partner
N-Able partner