PayPal sending “your card has expired” emails

This morning, I tweeted about an email I received from PayPal. 140 characters proved a little short to make my point :) This is what the email said (Dutch):

Uw creditcard nadert de vervaldatum

Beste Eelke Blok,

Hartelijk dank voor het gebruik maken van PayPal. We willen graag zorg dragen voor een optimale dienstverlening. PayPal wilt u daarom op de hoogte stellen van het feit dat uw creditcard de vervaldatum nadert.

Om van uw PayPal-rekening gebruik te kunnen blijven maken, adviseren wij u om uw creditcardgegevens bij te werken.

Druk op onderstaande knop ‘Ga naar PayPal.nl’ en log in op uw PayPal-rekening. Ga vervolgens naar het tabblad Profiel en kies ‘Kaart toevoegen of verwijderen’.

Ga naar PayPal.nl

Tip: u kunt nu ook probleemloos een bankrekening toevoegen aan uw PayPal-rekening.

Met vriendelijke groet,

PayPal team

In short, it says that my credit card is about to expire (which is true) and asks me to follow a link and update my credit card info. In my tweet, I said this reeks of Phishing.

Now, don’t get me wrong, I don’t think this actually is a phishing email. The links are actually from genuine PayPal domains.

I do, however, find it pretty irresponsible of PayPal to send around these emails. Basically, everyone who actually understands about Phishing is trying to tell everyone else to never follow any links in an email that is asking you to provide your credit card details, log into your home banking site, or provide any other personal data. And here comes PayPal, acting like all this doesn’t actually exist, happily inviting users to click their link.

PayPal, please stop sending emails like this and actually take the opportunity to explain to users that they should go to PayPal manually, and why.

Uw creditcard nadert de vervaldatum
Beste Eelke Blok,

Hartelijk dank voor het gebruik maken van PayPal. We willen graag zorg dragen voor een optimale dienstverlening. PayPal wilt u daarom op de hoogte stellen van het feit dat uw creditcard de vervaldatum nadert.

Om van uw PayPal-rekening gebruik te kunnen blijven maken, adviseren wij u om uw creditcardgegevens bij te werken.

Druk op onderstaande knop ‘Ga naar PayPal.nl’ en log in op uw PayPal-rekening. Ga vervolgens naar het tabblad Profiel en kies ‘Kaart toevoegen of verwijderen’.

Ga naar PayPal.nl

Tip: u kunt nu ook probleemloos een bankrekening toevoegen aan uw PayPal-rekening.

Met vriendelijke groet,

PayPal team

This entry was posted in Miscelaneous. Bookmark the permalink. Post a comment or leave a trackback: Trackback URL.

3 Comments

  1. Maarten Verbaarschot
    Posted 11 August 2010 at 22:46 | Permalink

    PayPal, please stop sending emails like this and actually take the opportunity to explain to users that they should go to PayPal manually, and why.

    But they did explain:

    Om van uw PayPal-rekening gebruik te kunnen blijven maken, adviseren wij u om uw creditcardgegevens bij te werken.

    [...] log in op uw PayPal-rekening. Ga vervolgens naar het tabblad Profiel en kies ‘Kaart toevoegen of verwijderen’.

    I personally don’t think it reeks of phishing at all. I think PayPal also wants to prevent people from getting frustrated because “suddenly, their account stopped working”, not realizing they need to manually update their credit card details. I don’t think they have much of a choice.

    And because it clearly links to an official PayPal domain, there’s really no need to worry. People that don’t look at the domain before using such a link are pretty easy to attack anyway, so that’s not really a reason for PayPal to not send these kind of e-mails.

  2. Posted 12 August 2010 at 08:15 | Permalink

    I don’t have a problem with the email in itself and I am happy they reminded me I should update my credit card details. The point is, they ask you to follow a link that’s in the email, while part of many anti-phishing strategies is to explain to users they shouldn’t do that. Yes, these users should also be explained they should double check the domain when they are on a website where they provide their details, but being suspicious of links in emails is, in my opinion, a healthy first line of defence.

  3. Theo Bijma
    Posted 14 September 2011 at 12:21 | Permalink

    I initially also thought it was phishing. Usually there is a typo in those e-mails and I scan for those. There actually is one in this e-mail:
    “PayPal wilt u daarom op de hoogte”

    (there is a t too many)

    Therefore I would say it does reek like phishing.

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>