Forum Moderators: buckworks
I thought I would let you know after I used my paypal account to pay you someone else tried to use my account to purchase a computer. You might want to check out your web security.
Obviously I do not know how freely the customer gives out their login information and thus the problem may not be with my site. But is it possible for my website to be compromised and somehow a hacker can capture the paypal info?
Without knowing more details of this particular incident, it's impossible to know what the real story is. There are way too many variables involved. As you mentioned, the customer may have giver her login to others. She may have a virus/Trojan on her computer that has logged her keystrokes or gove through her e-mail messages. It may be like the above virus and the message was sent to the same e-mail she uses for PayPal (realistically, how many non-tech savy people have more than 1 e-mail address?). Or it could have been some other scam e-mail sent to her e-mail. Or a security breach at another site she used and paid through PayPal.
Of course, it's also possible that your site may have been compromised as well. What processing are you doing on your site, or are you sending custoemrs directly to the PayPal site for the entire transaction?
All payment processing happens on Paypal. However, I do have a script installed on my site that sends a the customer a confirmation email after paying through Paypal. Interestingly, this customer claims they did not get an email. I should have mentioned this in my first post, but it slipped my mind at the time.
How would I find out if this script is a/the problem?
If the customer received an email that appeared to be a PayPal receipt for a payment they did not authorize, the customer should not click any links in the email, and should go to the PayPal website & log in to their account to see whether the payment actually occurred. If the payment does not appear in the account, then the receipt email was a spoof. If an unauthorized payment does appear, the customer should contact PayPal directly to report it.
I had some issues last week with a recurring bill on Paypal. So I sent them an email. I received an auto-reply within a few minutes and then I got another email re: problems with my account. It looked like the first one but it was a phishing email.
-Corey