Genuine PayPal emails with spoof URLs
by Chris Dawson
This post was written in October 2007; specific information contained within it may be out of date.
PayPal emails are corrupt this morning. They are arriving for valid transactions with the PayPal URL replaced by an error. The links in the email including picture links all refer to https://SECURE.UNINITIALIZED.REAL.ERROR.COM/uk/vst/id=xx

It has to be more than a little embarrassing for PayPal just as the number of phishing emails are falling and they’ve implemented domain keys to then insert a load of dodgy URLs into their payment notification emails.
Comments
5 Responses to “Genuine PayPal emails with spoof URLs”



This has been happening for about 2 weeks now. When you look at the affected transactions from within Paypal, all have the user’s email in place of the eBay user id for some reason.
It’s not the user id/email address that’s the problem, it’s the fact it’s a totally incorrect URL - that’s only appeared this morning
Steve is right, It has been happeing for a couple of weeks on a small percentage of payment emails (missing id and incorrect URL). I reported it to PayPal when I got the first one, have heard nothing since but still continue to receive them…
I think it started soon after their announcement re Domain keys..
Like Steve, I’ve been getting the secure.uninitialised etc. thing for a couple of weeks, but it appears to be fixed this morning.