Observed Signal · Jul 31, 2026 · Security Alert · Source: t3n · Impact: 2/5 · Sentiment: Negative

PayPal users targeted by 909€ phishing emails

Executive Signal Summary

Cybercriminals are circulating at least two PayPal-branded phishing email variants. One claims the recipient is owed a €95.66 refund and prompts users to click a link to claim it; the other alleges a €909 charge by merchant “Digistore24 GmbH” that will be debited within two days unless disputed. Both links direct to counterfeit, PayPal-styled webpages designed to harvest login credentials and personal and financial data. The messages use PayPal styling and urgency to appear legitimate, increasing the risk recipients will disclose sensitive information. Watchlist Internet reported the campaigns and t3n published a warning on 2026-07-31. Users are advised not to click links or buttons in such messages, to hover to inspect URLs, to mark suspicious emails as spam, and to verify account activity only by logging in through the official PayPal app or website.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Consumer-targeted PayPal phishing affects trust in email channels and payment brands; useful security advisory but not industry-shifting.

SIGNAL RADAR

Track PayPal Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Two phishing variants: a fake €95.66 refund request and a fake €909 charge allegedly to Digistore24 GmbH that threatens a debit within two days.
  • Email links lead to counterfeit PayPal-styled websites that harvest login credentials and personal/financial data.
  • Messages use PayPal branding and urgency to pressure recipients into revealing sensitive information.
  • Watchlist Internet reported the campaigns; t3n published a warning on 2026-07-31.
  • Protective actions: do not click links or buttons, hover to inspect URLs, mark suspicious messages as spam, and verify via the official PayPal app or website.

Connected Companies & Entities

4 Entities mapped

“The article warns that criminals are sending messages purportedly from PayPal and using the payment service's branding as a cover....”

“The page notes that external content from TargetVideo GmbH supplements the editorial offering on t3n.de....”

“The warning article was published on the t3n website (t3n – digital pioneers)....”

“An image credit in the article reads: 'Image: Shutterstock/Samuel Boivin.'...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Jul 31, 2026
Original Coverage Title: “909 Euro abgebucht? Paypal-Kunden müssen jetzt auf diese Mail achten”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Payments & FraudMar 26, 2026

Phishing Targets PayPal Users as Google Pay Links End

German reporting warns of a PayPal-themed phishing campaign that exploits users' awareness that PayPal will stop allowing new linkings with Google Pay/Google Wallet on Android after March 31. The phishing emails falsely claim a user’s card was removed and urge recipients to "update" credit-card details, which can lead to credential theft. PayPal states existing PayPal–Google Wallet links remain active unless the user removes them, resets the phone, or changes devices; only new link creation will be disabled after March 31. Consumer protection agencies advise ignoring and deleting such messages. The report notes PayPal also supports contactless payments directly via its Android app, reducing dependence on Google Pay linking.

Read assessment
Fraud & PhishingMay 18, 2026

Phishing Emails Claim Amazon Demands €8.99

t3n reports that scammers are circulating phishing emails that claim Amazon could not charge a customer's payment method and demand €8.99 for an Amazon Prime Video subscription. The email urges recipients to update their payment details via a prominent button; if victims enter credentials or card data, attackers can steal login information and cause larger financial damage. The article cites Mimikama's warning, explains that the low amount is intended to lower suspicion, and gives practical advice: do not click the email button, instead log in directly via Amazon's website or app to verify account status; contact your bank to stop unauthorized transfers and contact Amazon customer service if your account is compromised. The piece was published on 2026-05-18 by Marvin Fuhrmann on t3n.

Read assessment
Email & PhishingMay 3, 2026

Phishing Claiming to Be Tax Office: How to Spot Fakes

German consumer advocates and tax authorities warn of renewed phishing campaigns impersonating the Elster tax portal. Fraudulent emails vary in sender and content—promising refunds or including fake invoices—but aim to steal login credentials, bank or card details via links to bogus security portals. Elster states it only sends notifications by email and never transmits tax data, invoices, or requests for sensitive information (tax numbers, account numbers, PINs) as attachments or via email. Consumer groups recommend marking such messages as spam, not clicking embedded links, and checking tax matters only via the official Elster website or the responsible tax office. A GMX/Web.de survey cited in the article found 64% of people experienced digital fraud attempts in the previous year, with 47% receiving phishing emails.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.