AndyP & Lenore
29th December 2007, 02:00 AM
Sorry in advance for going on a bit but you'll see why if you have the time to read the following:
For those who buy/sell on eBay and have a Pay Pal (from now on called "PP") account, I thought I should share this rather scary experience.:eek:
I've had a PP account for a good few years - probably 6 or 7. Never had any problems with security until now.
I got an email from PP saying someone who had paid me money was disputing the payment. I was to visit their resolution centre and add my comments to the claim for them to proceed. At first I thought it was one of those phishing emails where they ask you to "confirm your details or the account would be closed" sort of things:rolleyes: . So I logged in to my PP account using the usual URL rather than the URL to click in the email. It took me straight to the resolution centre, rather than the usual account summary screen.
It turns out that a guy had paid me two payments; £380 ish and £430 ish for some football memorabilia stuff he had bought presumably from eBay. Nothing to do with me.:eek: Haven't sold anything on eBay for a year or two. Only use PP for the occasional eBay purchase (3 or 4 a year). The resolution options were aimed at genuine transactions where I could/could not prove the stuff had been delivered etc., there wasn't a button for me to click which said "WTF??? I know NOTHING about this!" so I had to call PP on Thursday to see what they had to say. I also noticed that "someone" had linked another bank account to my PP account. It was a UK registered bank account from "The Turkish Bank???" Alarm bells started to ring, big time.
Thursday came and I called them. At first I'm pretty sure it was a call centre in Asia that the call went through to, but the guy soon realised this was a more serious matter rather than a "I've forgotten my password" conversation. So I got put through to a lassie in Ireland who was very understanding and froze my PP account immediately. She's removed the Turkish bank details and they have refunded the poor bloke who paid me £800 odd for nothing.
Then today I went back in to my PP account to see what was happening. Perhaps in my ignorance - partly understandable taking into account I seldom use PP - I discovered a "Account history" button.
HOLY ****!!!:eek: :eek: :mad:
Presumably, the same person who hacked my PP account and added themselves a Turkish bank account has been paying himself out of the money he stole from the poor bloke who paid me for the goods he didn't receive. What a frikking mess. The hacker had the good grace to pay me about £12 too, for what reason I have no idea, but I have checked my bank account and that money did go in to my bank account. What is very scary is that if he had full control of my PP account (and I can only assume he did) he could have transferred a fair bit of money (you've all seen the price of popcorn lately) OUT of my bank account into my PP account then from my PP account in to his Turkish account!!!
Needless to say, I've emptied my UK bank account and given all the money to Lenore.
Now waaaaaaaaaaaaaaaaaaaaaaaaait A minute. [Thinks]. Is this some elaborate plot I wonder?:o :D
Seriously though, and joking aside, this is worrying. I know my own UK bank has a pretty secure method of logging in to electronic banking. It's shocking that PP don't have a similar system. If you have someones PP ID (usually their email address) and an idea what their password is, you have full control of their PP account. That's just wrong.
I think if I'm going to continue with any PP membership I'm going to have to open a bog standard UK bank account with nothing in it. Then just stick money in it when I need to pay money out of it.
A.:o
For those who buy/sell on eBay and have a Pay Pal (from now on called "PP") account, I thought I should share this rather scary experience.:eek:
I've had a PP account for a good few years - probably 6 or 7. Never had any problems with security until now.
I got an email from PP saying someone who had paid me money was disputing the payment. I was to visit their resolution centre and add my comments to the claim for them to proceed. At first I thought it was one of those phishing emails where they ask you to "confirm your details or the account would be closed" sort of things:rolleyes: . So I logged in to my PP account using the usual URL rather than the URL to click in the email. It took me straight to the resolution centre, rather than the usual account summary screen.
It turns out that a guy had paid me two payments; £380 ish and £430 ish for some football memorabilia stuff he had bought presumably from eBay. Nothing to do with me.:eek: Haven't sold anything on eBay for a year or two. Only use PP for the occasional eBay purchase (3 or 4 a year). The resolution options were aimed at genuine transactions where I could/could not prove the stuff had been delivered etc., there wasn't a button for me to click which said "WTF??? I know NOTHING about this!" so I had to call PP on Thursday to see what they had to say. I also noticed that "someone" had linked another bank account to my PP account. It was a UK registered bank account from "The Turkish Bank???" Alarm bells started to ring, big time.
Thursday came and I called them. At first I'm pretty sure it was a call centre in Asia that the call went through to, but the guy soon realised this was a more serious matter rather than a "I've forgotten my password" conversation. So I got put through to a lassie in Ireland who was very understanding and froze my PP account immediately. She's removed the Turkish bank details and they have refunded the poor bloke who paid me £800 odd for nothing.
Then today I went back in to my PP account to see what was happening. Perhaps in my ignorance - partly understandable taking into account I seldom use PP - I discovered a "Account history" button.
HOLY ****!!!:eek: :eek: :mad:
Presumably, the same person who hacked my PP account and added themselves a Turkish bank account has been paying himself out of the money he stole from the poor bloke who paid me for the goods he didn't receive. What a frikking mess. The hacker had the good grace to pay me about £12 too, for what reason I have no idea, but I have checked my bank account and that money did go in to my bank account. What is very scary is that if he had full control of my PP account (and I can only assume he did) he could have transferred a fair bit of money (you've all seen the price of popcorn lately) OUT of my bank account into my PP account then from my PP account in to his Turkish account!!!
Needless to say, I've emptied my UK bank account and given all the money to Lenore.
Now waaaaaaaaaaaaaaaaaaaaaaaaait A minute. [Thinks]. Is this some elaborate plot I wonder?:o :D
Seriously though, and joking aside, this is worrying. I know my own UK bank has a pretty secure method of logging in to electronic banking. It's shocking that PP don't have a similar system. If you have someones PP ID (usually their email address) and an idea what their password is, you have full control of their PP account. That's just wrong.
I think if I'm going to continue with any PP membership I'm going to have to open a bog standard UK bank account with nothing in it. Then just stick money in it when I need to pay money out of it.
A.:o