Observed Signal · Mar 26, 2026 · Deprecation · Source: t3n · Impact: 2/5 · Sentiment: Neutral
Phishing Targets PayPal Users as Google Pay Links End
German reporting warns of a PayPal-themed phishing campaign that exploits users' awareness that PayPal will stop allowing new linkings with Google Pay/Google Wallet on Android after March 31. The phishing emails falsely claim a user’s card was removed and urge recipients to "update" credit-card details, which can lead to credential theft. PayPal states existing PayPal–Google Wallet links remain active unless the user removes them, resets the phone, or changes devices; only new link creation will be disabled after March 31. Consumer protection agencies advise ignoring and deleting such messages. The report notes PayPal also supports contactless payments directly via its Android app, reducing dependence on Google Pay linking.
The change affects mobile payment flows and creates an immediate phishing risk for a large user base; relevant to commerce/payment UX and consumer trust but not industry-shifting for AdTech/MarTech.
Track PayPal Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- PayPal will stop permitting creation of new PayPal links in Google Wallet/Google Pay on Android from March 31.
- Phishing emails impersonating PayPal claim users' cards were removed and prompt recipients to update credit-card data.
- PayPal says existing PayPal–Google Wallet links remain active unless the user removes them, resets the phone, or changes devices.
- Consumer protection agencies advise recipients to ignore the phishing emails and move them to the spam folder.
- PayPal already supports contactless payments directly through its Android app.
Connected Companies & Entities
4 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
PayPal users targeted by 909€ phishing emails
Cybercriminals are circulating at least two PayPal-branded phishing email variants. One claims the recipient is owed a €95.66 refund and prompts users to click a link to claim it; the other alleges a €909 charge by merchant “Digistore24 GmbH” that will be debited within two days unless disputed. Both links direct to counterfeit, PayPal-styled webpages designed to harvest login credentials and personal and financial data. The messages use PayPal styling and urgency to appear legitimate, increasing the risk recipients will disclose sensitive information. Watchlist Internet reported the campaigns and t3n published a warning on 2026-07-31. Users are advised not to click links or buttons in such messages, to hover to inspect URLs, to mark suspicious emails as spam, and to verify account activity only by logging in through the official PayPal app or website.
Ad Buyers Face New Wave of Google Account Takeover Scams
Ad buyers managing Google Ads and Merchant Center accounts report sophisticated account takeover scams that hijack client accounts, drain funds, and sometimes lock out administrators for weeks. Incidents occurred between August and October, echoing earlier fraud documented by Malwarebytes. Earlier attacks used fraudulent Google Search links and fake sign-in pages, with 2FA prompts coming from outside the US (often Brazil). Newer variants are linked to Gmail-based phishing and other integrations, including suspected Salesforce involvement, with Google warning of related threat activity by Vietnamese actors. Google says it secures compromised accounts, restores advertiser access, and issues credits where appropriate. Agencies describe the attacks as opaque and difficult to attribute, with some reporting multi-million-dollar losses in Merchant Center budgets and partial refunds only via ad credits. The events highlight ongoing risks of account takeover fraud on the Google platform and the challenges of recouping losses while campaigns remain frozen.
US Government Excludes Microsoft from Visa Program
The US government has barred Microsoft from participating in the permanent residency process for foreign workers with H-1B visas, accusing the company of abusing the program. Vice President JD Vance stated that Microsoft laid off 6,000 American employees last year while benefiting from 6,300 H-1B visa holders. The Department of Labor, led by Keith Sonderling, will not accept new permanent residency applications from Microsoft, as well as several consulting firms and Adobe. This action comes weeks before the midterm elections and reflects the Trump administration's broader criticism of the H-1B program, which it claims disadvantages American workers. Microsoft has not yet responded. The move could impact the tech industry's ability to retain skilled foreign talent.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
