Loading stock data...

Fake Invoice Alert: PayPal Hit by TOAD Cyberattack Days After OpenAI Partnership

By: Ovie George

November 1, 2025

3 minute read

PayPal faces a new wave of fake invoice scams just days after announcing its partnership with OpenAI. Cybercriminals are using real PayPal email accounts in a sophisticated TOAD attack to steal user credentials and payment details.

Just days after PayPal announced a groundbreaking partnership with OpenAI to integrate payments into the ChatGPT platform by 2026, the fintech giant has become the target of a widespread fake invoice attack.

According to a Forbes report citing cybersecurity experts from KnowBe4, cybercriminals are exploiting a Telephone-Oriented Attack Delivery (TOAD) method to trick PayPal users with fraudulent invoices sent from legitimate-looking email accounts.

How the PayPal Fake Invoice Scam Works

The scam begins when users receive an email appearing to come from a real PayPal address. The email contains an invoice for products or services the recipient never ordered, often with an alarming amount and a phone number to call for dispute resolution.

Security experts warn that this phone number connects users not to PayPal, but to fraudsters who attempt to extract sensitive details such as credit card numbers, PayPal login credentials, or even direct payments.

“You receive an email from a real PayPal email address which contains an invoice for a large purchase you did not make, and a phone number for you to call if you want to dispute the charge,” warned analysts at KnowBe4. “The email is real, but the invoice is fake.”

TOAD Attacks Use Fear and Urgency to Deceive Victims

Known as a Telephone-Oriented Attack Delivery (TOAD) threat, this cyberattack technique leverages social engineering, using fear of financial loss or urgency to push victims into acting quickly.

Typically, these emails include:

  • A PDF invoice or money request attachment
  • A blank message body (another red flag)
  • A fake customer service number

Reports indicate the campaign has been ongoing for over a week, targeting PayPal users globally.

TOAD Attacks Use Fear and Urgency to Deceive Victims

Known as a Telephone-Oriented Attack Delivery (TOAD) threat, this cyberattack technique leverages social engineering, using fear of financial loss or urgency to push victims into acting quickly.

Typically, these emails include:

  • A PDF invoice or money request attachment
  • A blank message body (another red flag)
  • A fake customer service number

Reports indicate the campaign has been ongoing for over a week, targeting PayPal users globally.

PayPal Responds Amid AI Expansion Plans

This security alert comes shortly after PayPal’s collaboration with OpenAI, which aims to enable seamless payments and commerce within ChatGPT by 2026. The company has yet to release an official statement on the incident, but the timing highlights the growing risks facing fintech platforms as they expand into AI-driven ecosystems.

Conclusion

The fake PayPal invoice scam underscores the evolving sophistication of cybercriminals exploiting legitimate digital platforms. As PayPal continues to innovate with AI and cloud-based payment solutions, experts urge users to remain cautious, verify all communications, and prioritize cybersecurity awareness to avoid falling victim to scams.

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

Category

Feature Posts

If you’d like to get featured on our Entrepreneur Spotlight, click here to share your startup story with us.

Africa Innovation Watch Newsletter

Get the best of Africa’s daily tech to your inbox – first thing every morning.

Join the community now!