Looks like a new scam

Oct 08, 2020 Last reply: 5 years ago 71 Replies

To meet new regulations, Strong Customer Authentication (SCA) is being added into the PayPal login.



This means that when you login or pay with PayPal, you may be asked for a one-time code that we send via SMS to the phone number you have registered in your profile.



To keep using your PayPal account without interruption, please check that the phone number in your profile is correct. How to check your phone number: Login to your account or open the PayPal app on your phone. Select the settings icon at the top. Select Your Profile (desktop) or Personal Information (app). Check your phone number and edit if necessary.


I am a dinosaur! My mobile is 20 years old. I hardly ever use it. It's mostly switched off. I bought it for emergencies as our bungalow at the time was rather isolated and the landline phone went through a spell of being unreliable. I don't even know if it will receive texts (I assume that's how this code will be sent), or if it can, how I view them. If I give Paypal my landline phone number, will I get a sound version of this code that you're describing, i.e. someone speaking it?

Can't comment on whether the specific email you received is legit or a scam, but I've also received one. To be safe don't trust any links in paypal/bank emails, just go direct to the paypal website, login and check your details ...

SCA is definitely a thing.

formatting link

This does not even feature in my reasons for disliking PayPal,

OK, I've just set it up via my Paypal account, and got a spoken code on my landline, so it does work.

21st. century this way>>>>>>>:-) >

Is the correct answer regarding mobile phones.

All banks and building societies are doing the same for any electronic access to accounts. YBS used my landline number to send the code. Unfortunately they didn't take into account that I monitor all calls using my answerphone and they sent the code during the time my outgoing message was being sent.

You may have trouble with some of these security calls on a landline if you use phones with cold calling spam filtering.

I got a call from 'Barclaycard security'. They refused to tell me my Barclaycard number 'for security reasons'. I refused to answer any questions or provide any information as I was not satisfied this was a genuine call.

I think they called me three times. Turns out it was genuine.

Makes a lot more sense to do everything on the mobile and dump the landline now. That way everything is in one place and it works everywhere unless you are where there is lousy mobile coverage.

My issue is that I don't want to carry the mobile all round the house with me.

I have a landline phone in every room except the bathroom, and I can generally reach it within a few seconds.

NatWest Mastercard fraud dept. tell you to call back on the number printed on the card if you are concerned. The number on the website would be an alternative if you are fairly sure what site you are on. Which you can't necessarily be, but it is unlikely a private individual would be the subject of a two-pronged attack via DNS and telephone at the same time.

I do not have any financial Apps or data on my phone, but I can receive SCA numbers from my bank. I would have thought PayPal would use a secure message to the registered email address, on my computer.

All paypal want to do is send a code via SMS to your mobile (or speak it to your landline) they're not insisting you install the paypal app ... would you prefer a carrier pigeon option?

If you are worried about DNS spoofing, you can switch to a DNS provider that offers either DNSSEC or DNS over HTTPS (DOH).

Cloudflare is such a provider, their DNS IP's are 1.1.1.1 and 1.0.0.1

Your network's DHCP server must support DNSSEC or DNS over HTTPS

formatting link
and

formatting link

Or presumably I could use my network's DNS server, if I could be bothered to configure it for DNSSEC. But what I was saying is that I was *not* worried about DNS spoofing in the context.

if you are doing on-line bankingb you will be in ne place, Simply have teh phone beside you.

The smartphone is insecure and needs charging all the time, and updating, too. I might go back to my clam-shell mobile, which does texts and that's all I need, really. It's a lot lighter and has a decent battery life. We've all been suckered into thinking that we cant live without a smartphone.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required