Back to The Local Vocal
The Local VocalMedium
Phishing🎭 PayPal
Email
Medium risk PhishingEncountered ViaEMAIL 15 July 2026
RegionOtagoNew Zealand

Fake PayPal Account Review Emails Are Reaching Your Staff

PayPal-spoofed phishing emails target staff with fake account review alerts to harvest credentials via fraudulent login pages.

A phishing campaign impersonating PayPal is designed to harvest your account credentials by convincing your staff to click through and "confirm" personal and financial details. If acted upon, the consequences extend beyond a compromised PayPal account — reused passwords, linked payment methods, and stored financial data all become accessible to the threat actor, exposing your organisation to fraud and potential downstream compromise of other services.

This campaign has been observed across multiple local organisations, with a cluster of messages appearing in NZ inboxes over a short window spanning several days. The cross-organisational spread suggests an automated distribution effort rather than a targeted attack, meaning your staff are likely to encounter this regardless of industry or size.

The email presents a convincing PayPal template — familiar branding, a measured tone, and a plausible pretext around keeping account details current. However, the sending domain has no affiliation with PayPal whatsoever, originating from a French-registered domain with no legitimate connection to the brand. Despite a passing DKIM result, both SPF and DMARC checks fail, indicating the message was not authorised by PayPal's mail infrastructure and should not have passed as legitimate correspondence.

What makes this campaign particularly worth noting is the combination of a soft-failing SPF result alongside a DKIM pass — a configuration that can cause some filtering systems to treat the message more leniently than a hard fail would warrant. This mixed authentication profile is increasingly used by threat actors to slip past automated defences while still failing the composite authentication check that matters most. The email body also trails off mid-sentence in its feature-restriction warning, suggesting a templated payload that may be part of a broader, evolving kit being reused across multiple campaigns.

Email authorisation
SPF
pass
DKIM
pass
DMARC
pass
COMPAUTH
pass
Domain authentication
Sender / From domain
localiq.com
Reply-To domain
sph.com.sg ⚠ mismatch
Domain age
7631 days old
Email Sample
Email Sample screenshot
Domain Reputation
Abuse score
15/ 100Low
ISP (Internet Service Provider)
Regional Host
Function:Function Unknown
Reputation:Reputation Unknown
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Delete the email immediately without clicking any links or downloading attachments, as the sender domain "avvv.fr" is a French domain with no legitimate connection to PayPal.
  • Report the phishing email to CERT NZ at certanz.govt.nz and forward it to PayPal's official phishing address (phishing@paypal.com) to help protect other Kiwi businesses.
  • Verify your PayPal account status by navigating directly to paypal.com in your browser — never through links in unsolicited emails — to confirm whether any genuine account action is required.
  • Alert your staff and colleagues about this specific campaign, sharing the sender address "info@avvv.fr" and subject line "Review Your Account Information" so they can recognise and avoid it.
  • Enable multi-factor authentication (MFA) on your PayPal account and any other business financial platforms to reduce the risk of unauthorised access if login credentials have been compromised.
PayPal logo
Is it real?
Got an email from PayPal?

See what a genuine PayPal message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing