• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Techphishing

Why PayPal and American Express may be the next hot targets for low-level hackers

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
January 21, 2020, 5:30 PM ET

Hackers are going after PayPal and American Express usernames and passwords using a phishing scheme that has previously targeted Amazon and Apple, according to research released Tuesday by security company ZeroFOX.

An operation on the dark web called 16Shop started selling phishing kits that target PayPal and American Express customers this month, ZeroFOX says. The digital tackle boxes, which cost less than $100, include everything a low level hacker would need to launch a phishing attack against customers of both companies .

“Phishing kits work very similarly to a marketing platform for sending and tracking email,” says Zack Allen, director of threat operations at ZeroFOX. The software marketers use—legally—helps to automate the process of sending email on behalf of the companies by tracking clicks, controling messaging, shaping content based on your geographic location or Internet browsers, and scheduling marketing campaigns.

The PayPal phishing kit, obtained by ZeroFOX, came with the option of buying additional features, such as customer support, customized templates and automated messages.

“You purchase the software to perform the attack, and some of these kits will reduce the complexity of deploying the attack by streamlining it for the operator,” Allen said.

The phishing kits are just the latest example of how cyber crime and other nefarious tools, such as deepfake video makers, are making complex technology more accessible to the masses.

As the economy moves towards more platform-base capitalism—like buying goods or services through Facebook, Instagram, or Uber, for instance— cyber criminals will follow suit, trying to infiltrate the transactions, says Allen. “We already see this with ransomware-as-a-service and botnets for hire,” he says. “Cyber criminals are now realizing the total addressable market for phishing-as-a-service.”

The news comes as cyber attacks that exploit human weaknesses continue to rise. A 2019 cybercrime study by Accenture said cyber criminals have adapted their attack methods by targeting the human layer—typically the weakest link in cyber defense—increasingly using ransomware, phishing, and social engineering attacks as an entry point. Last year, Kaspersky Labs released a report that detailing a rise in phishing attacks in 2018. The security company found that phishing attacks had more than doubled over the previous year.

Last month, the phishing rate across industries was 1 in 10,527 emails, according to Symantec’s monthly threat report, which shows just how prevalent phishing attacks are. However, that number fluctuates—it was 1 in 5,585 the previous month.

With phishing attacks expected to be on the rise this year, Allen said it’s important to remain vigilant when opening email or messages on social networks.

One way to do that is to check the email address link before clicking. Phishing scams often come from addresses that look legitimate, but might have a simple misspelling.

“Delivery mechanisms tend to be via email or social/digital platforms, and give an enticing message or a call-to-action to get you to click a link. The fake domains may contain the brand name to help convince victims the legitimacy of the website,” said Allen. “Just know that legitimate companies will never ask you for your personal information via these channels.”

More must-read stories from Coins2Day:

—A.I. In China: TikTok is just the beginning
—Inside big tech’s quest for human-level A.I.
—Medicine by machine: Is A.I. The cure for the world’s ailing drug industry?
—A.I. Breakthroughs in natural-language processing are big for business
—A.I. Is transforming the job interview—and everything after

Catch up with
Data Sheet, Coins2Day’s daily digest on the business of tech.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.