Suspicious
Phishings targeting PayPal
Suspicious and active websites
Phishings targeting Paypal
Suspicious and active websites
Active
11
New (7d)
1
Trend (7d)
—
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-09-07 03:30 | 2026-09-05 13:07 | ![]() |
GSB OpenPhish | Details | |
| 2026-09-07 03:30 | 2026-08-27 05:01 | ![]() |
OpenPhish TweetFeed | Details | |
| 2026-09-07 03:30 | 2026-08-22 13:02 | ![]() |
OpenPhish | Details | |
| 2026-09-07 03:30 | 2026-08-13 01:02 | ![]() |
OpenPhish | Details | |
| 2026-09-07 03:30 | 2026-08-12 17:26 | ![]() |
GSB | Details | |
| 2026-09-07 03:30 | 2026-08-05 17:26 | ![]() |
GSB | Details | |
| 2026-09-07 03:30 | 2026-07-30 01:01 | ![]() |
OpenPhish | Details | |
| 2026-09-07 03:30 | 2026-07-28 01:02 | ![]() |
OpenPhish | Details | |
| 2026-09-07 03:30 | 2026-07-23 12:01 | ![]() |
TweetFeed | Details | |
| 2026-09-07 03:30 | 2026-06-29 01:02 | ![]() |
OpenPhish | Details | |
| 2026-09-07 03:30 | 2026-05-01 01:01 | ![]() |
OpenPhish | Details |
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://paypal.cardpaysecurit…
GSB OpenPhish |
![]() |
Details |
| http://paypal3.vercel.app
OpenPhish TweetFeed |
![]() |
Details |
| https://paypal-password.blogs…
OpenPhish |
![]() |
Details |
| http://pay.paykmc.com/paypal/…
OpenPhish |
![]() |
Details |
| https://confirm-your-account-…
GSB |
![]() |
Details |
| https://paypal.com-websppsc-v…
GSB |
![]() |
Details |
| https://paypalcorp.blogspot.c…
OpenPhish |
![]() |
Details |
| https://paypal-secure.vercel.…
OpenPhish |
![]() |
Details |
| http://paypal-refund.com
TweetFeed |
![]() |
Details |
| https://paypal-signin.blogspo…
OpenPhish |
![]() |
Details |
| http://paypal-logiin.blogspot…
OpenPhish |
![]() |
Details |
AIHow to verify a real PayPal URL
- Legitimate PayPal URLs always end in
paypal.com(e.g.www.paypal.com,account.paypal.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not PayPal. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
paypal.comfrom your browser bookmark or type the domain manually. - Real PayPal pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.










