How to cancel money request on paypal

While there’s no shortage of PayPal scams going around at any given time, this PayPal payment request scam leverages social engineering tactics without having to rely on a link that could be detected by phishing protection solutions.  

Social engineering is a type of phishing attack that uses psychological manipulation to trick individuals into divulging sensitive information or performing actions that may be against their own interests. The goal is typically to gain access to confidential information or systems that can be used for fraudulent or malicious purposes.  It’s increasingly concerning both individuals and organizations as it can be difficult to detect.  Especially in cases where there is no phishing link included like the payment request scam example detailed in this blog.  

What Does the PayPal Payment Request Scam Look Like?

PayPal has a feature where anybody can request money from PayPal accounts on the PayPal website. 

How to cancel money request on paypal

When the request is made, the requesting party can add a note in the request which is intended to describe the reason for the payment.  Importantly, because the note is a feature of PayPal and actually comes from the PayPal notification system with an email address of [email protected], it’s technically a legitimate email message but it contains a malicious note. 

How to cancel money request on paypal

Attackers are using social engineering to exploit this note feature to trick users into believing their PayPal accounts have been used unlawfully for a purchase, advising them to call a support number to cancel the payment request.  Users that fall for the tactic and call the support number may quickly find themselves a victim of this payment request scam.  Below is a screen capture of an actual request sent as part of this PayPal scam.  In the note you can see that the attacker is attempting to make it look like an official notice from PayPal complete with a phone number to call (no phishing link).

How to cancel money request on paypal

According to the note, all the user needs to do is cancel the request and obviously not send the attacker funds. For the non-technically minded, users may not actually fully understand that it’s just a payment request as opposed to an actual debit or deduction. Contrary to the note, no transaction has actually occurred.

The attackers in this particular PayPal payment request scam are wise to the fact that users, when facing a suspicious request, perform a quick google search to validate or verify whether or not such a request is a known scam.  Knowing this is common behavior, the attackers have cleverly placed google ads that appear to point to the PayPal website.  The ad actually points to a spoofed domain that is yet another attempt to trick a user.  Below is a screenshot of the google ad.

How to cancel money request on paypal

What to Do if You Receive a Suspicious Payment Request

zvelo does not advise using google, or any other search engine, to validate whether or not a suspicious message is in fact a scam.  Attackers can — and do — use online ads to further their attempts to exploit users.

PayPal has the following notice posted in the help center on the website:

“Received a suspicious email, message, invoice or money request? Don’t reply, open links, download attachments, or call any listed phone numbers. We’ll never ask for your PayPal password or financial details by email or message, or over the phone.  Forward suspicious messages to [email protected] and then delete them.”

READ:  Impact and Implications of the 2021 Malicious Trends

If you have received one of these PayPal payment requests, there is an option to cancel the transaction from within the PayPal app or on the website.  Additionally, users have the option to report suspicious messages directly to PayPal as indicated by the message above. 

An Important Note:  

The driving force behind why we do what we do here at zvelo is to make the internet safer and more secure.  And even though our solutions are not directly geared for end user consumption, they are very much aimed at protecting end users.  While those reading this blog may be well aware of these sneaky social engineering tactics, it’s important to remember that we all know others who are less savvy when it comes to recognizing these attacks whether it be our parents, grandparents, teenagers, or friends.  As the Holiday season is particularly active, please take a moment to share the details of this attack with those who may need a reminder to be extra vigilant. 

What happens if someone requests money on PayPal?

The recipient will receive either an email or message with a link, through which they can make a payment directly to your PayPal wallet¹. You can add a note and explanation to your request, and use it for either personal or work use — although different fees apply for business transactions².

Can I cancel an order through PayPal?

Neither you nor PayPal can cancel an order, but the merchant might be able to cancel it for you. If you need to cancel an order or authorization, please contact the merchant. To see the seller's contact details: Go to Activity.

How do I cancel a pending authorization on PayPal?

Log in to your PayPal account at https://www.paypal.com..
Click the History tab..
Click the Details button associated with the authorization you want to void..
On the Transaction Details page, click on the Void button associated with the authorization..
Verify the void details on the Void Authorization section..

Why is there no cancel button on PayPal?

If you do not see the option to cancel the transaction, this means that the transaction has been completed and you will need to request a refund from the account holder. To proceed to cancel an unclaimed transaction, simply click the 'Cancel' button.