# A fake PayPal phishing website is using "Let's Encrypt" certificate

**URL:** <https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760>\
**Category:** Help\
**Created:** [October 7, 2016, 6:55am UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760 "2016-10-07T06:55:21Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![cycle6](https://avatars.discourse-cdn.com/v4/letter/c/a698b9/32.png) [@cycle6](https://community.letsencrypt.org/u/cycle6)\
**Post date:** [October 7, 2016, 6:55am UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/1 "2016-10-07T06:55:21Z")

</div>

I just received a phishing scam email that pretends to be from PayPal. And the hyperlink in the email leads to a phishing site has SSL certificate. And it seems the certificate is issued by “Let’s Encrypt”.

The URL is: “[paypal.com.webapps-mpp-accounts.com](http://paypal.com.webapps-mpp-accounts.com)”. Add https will display the SSL certificate.

Of course the site’s login page cannot verify your login credential. But if you happened to entered your real login credential, they will keep the record and they’ll have access to your PayPal account later.

I figure I should warn you guys incase you haven’t noticed this. I’ve sent an email to your [security@letsencrypt.org](mailto:security@letsencrypt.org) but it bounced back. So I registered and posted here.

best regards,

C6, a random web dev

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [October 7, 2016, 7:12am UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/2 "2016-10-07T07:12:34Z")

</div>

Let’s Encrypt has a dedicated email address ([cert-prob-reports@letsencrypt.org](mailto:cert-prob-reports@letsencrypt.org)) for these reports. Might get handled faster that way. (Hopefully, that one doesn’t bounce. 😄)

I went ahead and [reported](https://www.google.com/safebrowsing/report_phish/) the site to Google’s Safe Browsing as a phishing site, which should eventually prevent them from getting additional certificates for that domain (as well as block access in many browsers).

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [October 7, 2016, 4:12pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/3 "2016-10-07T16:12:54Z")

</div>

Hi @cycle6

Thanks for bringing this to our attention. I appreciate it.

Could you share the bounce message & the full raw email headers from when you tried to unsuccessfully email `security@letsencrypt.org` ? I just tested delivery to that address and it seemed to work, perhaps your message was itself flagged as a phishing attempt?

Thanks again!

---

<div class="post-metadata">

**Author:** ![TCM](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@TCM](https://community.letsencrypt.org/u/TCM)\
**Post date:** [October 7, 2016, 4:15pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/4 "2016-10-07T16:15:24Z")

</div>

> [@cycle6](#):
>
> The URL is: "[paypal.com.webapps-mpp-accounts.com](http://paypal.com.webapps-mpp-accounts.com)". Add https will display the SSL certificate.

That's a hostname. And yes, the certificate will happily certify that you are indeed talking to the right criminal and not some other criminal.

Maybe you are making assumptions about what a SSL cert certifies? It's not supposed to certify a "safe" website for whatever values of "safe" may be appropriate.

---

<div class="post-metadata">

**Author:** ![cycle6](https://avatars.discourse-cdn.com/v4/letter/c/a698b9/32.png) [@cycle6](https://community.letsencrypt.org/u/cycle6)\
**Post date:** [October 7, 2016, 4:15pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/5 "2016-10-07T16:15:47Z")

</div>

Oh thx for the tip 🙂  
Yeah I sent to Google as well. But doesn’t look like Google’s doing anything.

The reason I feel need to make a post is because the SSL certificate almost fooled me. Cus I thought if the website has ssl certificate it should be kinda legit. But that URL does look “phishy”, so I compared the live PayPal URL with the phishing site URL, looks different. Also the SSL certificates are different. Then I entered some fake login credential to the phishing site, it accepted without any problem.

Anyway, lesson for me is: from now on, any website send me email ask me to login to do something. With SSL or not I’m gonna try enter some fake certificates to test it first. XD

---

<div class="post-metadata">

**Author:** ![TCM](https://avatars.discourse-cdn.com/v4/letter/t/a587f6/32.png) [@TCM](https://community.letsencrypt.org/u/TCM)\
**Post date:** [October 7, 2016, 4:16pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/6 "2016-10-07T16:16:34Z")

</div>

> [@cycle6](#):
>
> I thought if the website has ssl certificate it should be kinda legit

That is a major mistake you must not make.

---

<div class="post-metadata">

**Author:** ![cycle6](https://avatars.discourse-cdn.com/v4/letter/c/a698b9/32.png) [@cycle6](https://community.letsencrypt.org/u/cycle6)\
**Post date:** [October 7, 2016, 4:33pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/7 "2016-10-07T16:33:58Z")

</div>

Yes I thought that was the case too. Next time maybe I’ll not use the full URL.  
Also if you have a report section for reporting miss use of your certificate, I’ll use that next time. I guess "cert-prob-reports@letsencrypt.org" should the one?

Thanks a lot, here’s the message raw header from the email I sent:

From: Paul Z [CYCLE6@hotmail.com](mailto:CYCLE6@hotmail.com)  
To: "security@letsencrypt.org" [security@letsencrypt.org](mailto:security@letsencrypt.org)  
Subject: You have issued certificate to a fake PayPal Phishing scams website  
Thread-Topic: You have issued certificate to a fake PayPal Phishing scams  
website  
Thread-Index: AQHSH/VYEcqg4/Crs0+GZaBLFf7u2A==  
Date: Thu, 6 Oct 2016 11:28:08 -0600  
Message-ID:  
[YTXPR01MB01431EE41074BD667FB9EC9489C70@YTXPR01MB0143.CANPRD01.PROD.OUTLOOK.COM](mailto:YTXPR01MB01431EE41074BD667FB9EC9489C70@YTXPR01MB0143.CANPRD01.PROD.OUTLOOK.COM)  
Content-Language: en-CA  
X-MS-Has-Attach:  
X-MS-Exchange-Organization-SCL: -1  
X-MS-TNEF-Correlator:  
Content-Type: multipart/alternative;  
boundary="_000\_YTXPR01MB01431EE41074BD667FB9EC9489C70YTXPR01MB0143CANP_"  
MIME-Version: 1.0

–_000\_YTXPR01MB01431EE41074BD667FB9EC9489C70YTXPR01MB0143CANP_  
Content-Type: text/plain; charset="iso-8859-1"  
Content-Transfer-Encoding: quoted-printable

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [October 7, 2016, 4:35pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/8 "2016-10-07T16:35:38Z")

</div>

> [@cycle6](#):
>
> Also if you have a report section for reporting miss use of your certificate, I'll use that next time. I guess "[cert-prob-reports@letsencrypt.org](mailto:cert-prob-reports@letsencrypt.org)" should the one?

Yup 👍 - thanks!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 6, 2016, 4:47pm UTC](https://community.letsencrypt.org/t/a-fake-paypal-phishing-website-is-using-lets-encrypt-certificate/20760/9 "2016-11-06T16:47:34Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
