Meeting location for the 2024/2025 Season will be at J.A. Dulude arena.  Meetings start at 7 pm.

Check your Paypal account

Started by Greatwhite, July 18, 2011, 09:35:00 PM

Previous topic - Next topic

Greatwhite

Last week, I got an email out of the blue from Paypal indicating that I had made changes to my billing subscriptions, for "eBay International AG".  Well, not only had I not made any changes, I hadn't even logged into my paypal account in the last month.

So I logged on, and noticed that I had a subscription open with a maximum transaction size of $365,000 per day.  Paypal and eBay claim that this "business" is for automatic payment of seller fees to eBay.  Well, I haven't ever sold anything on eBay and have no use for this.  Further research on that business revealed a lot of people complaining about unexplained payments there around the $20 mark - and one guy got hit for $350ish.

I inactivated that subscription immediately and changed my password.  2 days later, my Paypal account got locked for violation of section 10.4 of their user agreement.  That agreement indicates that Paypal cannot be used to sell counterfeit items.  When I asked what I did that triggered that, I was referred to some ebay user id that I hadn't heard of.

I googled the user id, and came up with a "removed" eBay auction for some "authentic silver bracelet".

It appears that *somehow*, someone linked that ebay account to my paypal, which created the eBay International AG subscription to be created.  If I hadn't cancelled that subscription, I probably would have been hit with a weird charge very soon.

A quick call with Paypal cleared up the locked account.

So if  you have a Paypal account, log into Paypal, go to Profile, My Money, My Preapproved Payments and see if there's eBay International AG in there.  If you're not a hardcore eBay seller, there is NO reason to have that.

Thunda

Thanks for the heads up.  I checked but thankfully nothing like that on mine... will keep a eye on it though.

dan2x38

A few years back got an email supposedly from PayPal. I opened it and they wanted me to verify my personal account info... NO FREAKIN' WAY!!! I called them and spoke to the fraud department. They informed me they send NO emails to you unsolicited. If there is an issue with your account they would lock the account and wait for you to reply was the short answer. If they ever had to send an email they would ask for no personal data what's so ever!!! I sent them the email for investigation.

NEVER reply to any banking, Microsoft or other such enterprises unless you know it was initiated by you to communicate with them. Then by email do not send personal info used only secured sites - look for the padlock!

In other words be careful very careful always and never give your financial/personal info away over the Internet!!!!!!
Voltaire:
"I may not agree with what you have to say,
but I'll defend to the death your right to say it."

JetJumper

Just curious about one thing.  I am not asking you to tell me what your password was, but I am wondering how strong it was.  I use a very complicated password for most banking things and have never had an issue.  I am an avid Paypal user as well and never run into any paypal issues at all.  

The other common way that people obtain passwords for money related sites is Trojan virus'.  Once on the system they typically report back any passwords you use on specific sites.  It may sit in limbo for a while, but eventually they are going to attempt trying "that account".  If you have had Trojans in the past yet did not change your passwords, I suggest you do that.

Just my 2 cents on how people obtain access to information like this.
.: JetJumper's Zone :.

dan2x38

Keyloggers are very common today and can go totally undetected. A keylogger can record everything you type then send the log to an email address untraceable. These are easy to pick up surfing questionable sites. If your security software: anti virus, anti spam, anti phising, etc. are up to date to stand a fighting chance. Sitting behind a firewall and router really helps. If ever you notice major slow downs,  internet activity without being online or downloading something run a test.

There are some real major online security scan scams!!! Really make sure if you use these they are from reputable vendors and their site. Better yet don't! Invest in a worthwhile security system same as you would for a good filter, light and heater for your tank - ya cheap out ya just might pay the ultimate price...
Voltaire:
"I may not agree with what you have to say,
but I'll defend to the death your right to say it."

Greatwhite

If you guys want me to see if your credit cards have been hacked on the internet, send me your card numbers and expiry dates and I'll look them up freee!! :)  (just kidding, don't)

I wish I could say that a keylogger was to blame here, it would certainly make it an easier thing to lock down.  But, to be honest - I have no idea how the guy could have linked to my account.  My password is strong, and my PCs are very secure. 

I am actually the self-proclaimed king of phishing email detection too.  I used to play World of Warcraft, and managed to get on every possible mailing list for those jerks.  I have also gotten numerous fake emails from eBay and Paypal.  I've seen them all, and can write a very short book on how to tell if the email is real or fake.  I've even been on the crappy end of a car buying scam when some Nigerian Prince wanted to buy my 2006 Hyundai Tucson through a western union wire transfer held in escrow until receipt of the car...  That was a brilliant scam!

These emails I got were not fakes this time.  I went straight to the Paypal site directly rather than clicking on links to confirm that there was actually a billing change made.

The thing is, I think you just need an email address to link to the Paypal account from eBay and I don't know if it even asks for a password.  That eBay International AG "business" appears to be added when you try to start an auction.

Without knowing the full nature of the scam, I don't know how the guy could have gotten money unless he was planning on invoicing after the purchase was made from his own Paypal account (or another billing system) and have the seller fee come from mine.  That's the only way I could see him getting any money at all.

This is the first time in ~10 years of having my Paypal account that I've run into any problems.

Some people aren't lucky enough to catch this before any problems arise because they let their Paypal account go dormant or have it linked to an address that they don't monitor.  I'd venture a guess that there's a pretty high percentage of people in that category, which is what makes it a viable scam.

Darth

if you ever get an email that is suspicious if you hover your mouse over the link it will reveal the web address in the bottom right of your screen if it says it's going to http://ebay.com your fine but if you see anything other then website you should be going to like an ip address of or something else its phishing for paypal or anything secure like your bank website that shows after you hover should always show httpS the s is very important as it means secure if you get a message from paypal and it is http://paypal.com be leary paypals real site will always have https

Greatwhite

Quote from: Darth on July 19, 2011, 08:39:33 AM
if you ever get an email that is suspicious if you hover your mouse over the link it will reveal the web address in the bottom right of your screen if it says it's going to http://ebay.com your fine but if you see anything other then website you should be going to like an ip address of or something else its phishing for paypal or anything secure like your bank website that shows after you hover should always show httpS the s is very important as it means secure if you get a message from paypal and it is http://paypal.com be leary paypals real site will always have https

Darn.. Looks like Darth beat me to writing my very short book on how to detect a phishing email. :)

I like when addresses are something like paypal.com.account.management.com.  Every time I see it I giggle because SOMEONE will fall for it.

Darth

my favs are when I get emails from banks I don't bank with those are the best

dan2x38

Well I thought my Paypal account was hacked today. I deposited a cheque and the receipt showed I was $$$ lighter after the deposit. What the? I was thinking of this damn thread right off. Well I got home and checked my account I'd forgotten I'd purchased the tickets for the Harry Porter movie. D'OH  LOL
Voltaire:
"I may not agree with what you have to say,
but I'll defend to the death your right to say it."

Greatwhite

Quote from: dan2x38 on July 19, 2011, 09:42:51 PM
Well I thought my Paypal account was hacked today. I deposited a cheque and the receipt showed I was $$$ lighter after the deposit. What the? I was thinking of this damn thread right off. Well I got home and checked my account I'd forgotten I'd purchased the tickets for the Harry Porter movie. D'OH  LOL

Glad to add to your paranoia!! :)

Dorrie

Quote from: Darth on July 19, 2011, 12:50:22 PM
my favs are when I get emails from banks I don't bank with those are the best

My favorites ones are alledgedly from the IRS saying they're coming to get me.
Funny since I've never even set foot in the US and don't have cross-border business transactions.
Or maybe they're taxing all that money coming from Nigeria any day now through a wire transfer?
Yeah, that's gotta be it. I'm sure sure though that if I write back to His Royal Highness he'll clear it right up by telling them he selected me because he heard so many good things about me in Nigeria, another country where I've never been. I guess word gets around on the Internet.

Want to hear the kicker? People in Nigeria are getting scammed by people claiming to be from Canada. Now that's irony.

And if you desire to imagine one guy's answer to spammers: http://www.leasticoulddo.com/comic/20090306 and http://www.leasticoulddo.com/comic/20090307.

JD

I went and checked my account...it had a subscription too. It was for up to $375,000.00 per month to cover eBay fees.
Needless to say I cancelled it. Will see what happens.


Quote from: Greatwhite on July 18, 2011, 09:35:00 PM
Last week, I got an email out of the blue from Paypal indicating that I had made changes to my billing subscriptions, for "eBay International AG".  Well, not only had I not made any changes, I hadn't even logged into my paypal account in the last month.

So I logged on, and noticed that I had a subscription open with a maximum transaction size of $365,000 per day.  Paypal and eBay claim that this "business" is for automatic payment of seller fees to eBay.  Well, I haven't ever sold anything on eBay and have no use for this.  Further research on that business revealed a lot of people complaining about unexplained payments there around the $20 mark - and one guy got hit for $350ish.

I inactivated that subscription immediately and changed my password.  2 days later, my Paypal account got locked for violation of section 10.4 of their user agreement.  That agreement indicates that Paypal cannot be used to sell counterfeit items.  When I asked what I did that triggered that, I was referred to some ebay user id that I hadn't heard of.

I googled the user id, and came up with a "removed" eBay auction for some "authentic silver bracelet".

It appears that *somehow*, someone linked that ebay account to my paypal, which created the eBay International AG subscription to be created.  If I hadn't cancelled that subscription, I probably would have been hit with a weird charge very soon.

A quick call with Paypal cleared up the locked account.

So if  you have a Paypal account, log into Paypal, go to Profile, My Money, My Preapproved Payments and see if there's eBay International AG in there.  If you're not a hardcore eBay seller, there is NO reason to have that.

Nerine

that's MY money...the Nigerian prince promised me I'd get the millions for my sick fatherless 19 children...he died in a tragic farming accident, run over by a herd of 'shrooms... and they wrote back and said all I had to do was send my passport :D hahaha
55 Gallon: Zamora Woodcats, Gold Gourami, Severum, Convicts
Misc tanks: Glo Light Tetras, Harlequin Tetras, Danios, Platies, Guppies, Otto cats
Breeding: Platies, Guppies, Convicts

Fishnut

That's rediculous!! 

I very rarely use my paypal account (it's been over a year since I used it) and I have a pretty complicated password...which I had to write down and put in our secret hiding spot for future reference.

No odd charges but I'm going to log in and check my account...when I have time to find the password in my secret hiding spot!!

Greatwhite

Yep...  Any subscription that can charge you up to $375,000 on any given day is NOT ok in my books.

I certainly didn't add it, nor did I agree to it being added 2 weeks ago.

IF you sell anything on eBay, there are one-time ways to pay the seller fee that does not require any subscription... And if the claims that people reported of that subscription charging them improperly are true - it's better to remove that ability altogether.

Nerine

how do you check subscriptions? I dont see anything?
55 Gallon: Zamora Woodcats, Gold Gourami, Severum, Convicts
Misc tanks: Glo Light Tetras, Harlequin Tetras, Danios, Platies, Guppies, Otto cats
Breeding: Platies, Guppies, Convicts