Don’t Get Played: Exposing the PlayStation PayPal Invoice Scam
Written by: Thomas Orsolya
Published on:
Gaming and tech enthusiasts beware – a devious new email scam has emerged that leverages two major brands, PayPal and PlayStation, to target unsuspecting consumers.
These fraudulent PlayStation PayPal invoices claim you owe money for an expensive PlayStation console order processed through your PayPal account. But in reality, you never made such a purchase.
The scam combines convincing PlayStation and PayPal branding and logos with urgent threats to fool recipients into calling the provided phone number. But the call centers are entirely fake – clever schemes by criminals who will steal your money if given the chance.
This comprehensive guide will uncover all the deceptive tricks used in the PlayStation PayPal invoice scam campaign. With knowledge of how to spot the warning signs, you can keep your wallet and identity protected. Don’t let enthusiasm over gaming tech blind you to this fraud.
This article contains:
An Emerging Threat Targeting PlayStation and PayPal Users
Reports have rapidly increased of the PlayStation PayPal invoice payment scam as fraudsters seek to capitalize on the popularity of Sony gaming platforms and PayPal digital payments.
The scam emails include:
Realistic PlayStation and PayPal logos and branding
A large invoice for a PlayStation console plus games and accessories
Claim the order was processed through your PayPal account
Threats your PSN account will be suspended if the fake bill isn’t paid
A phone number to call for resolving the supposed unauthorized order
But it’s all a fraudulent ploy to deceive you and steal your money. These emails have nothing to do with Sony, PlayStation, or PayPal in reality. Here’s what you need to know to recognize this scam.
Spotting the Deceptive Tactics in Fake PlayStation Invoices
The PlayStation PayPal scam relies on credible branding and fabricated invoices to trick anxious recipients. Watch for these signs an invoice is fake:
Price matches a real PlayStation model like $499 for a PS5 Digital Edition
Includes additional realistic purchases like extra controllers and games
A due date that creates false urgency to pay quickly
Threat to suspend your PSN account if unpaid
PayPal logo to make it seem processed through your account
Phone number provided to call about the invoice
Sony and PayPal logos and copyrights copied from real sites to appear legit
But upon closer inspection, there are always red flags:
Grammatical/spelling errors uncommon for real companies
Unrecognized invoice number not found in your PayPal account
Threats of account suspension when no notification inside PayPal
Requests to call a number rather than login to PayPal to resolve issues
With awareness of these scam giveaways, you can identify and avoid fraudulent PlayStation PayPal invoices. Don’t let familiar logos trick you – scrutinize the full details.
Anatomy of the Fake PlayStation PayPal Invoice Scam Emails
To help you instantly recognize these fraudulent emails, let’s break down the common elements contained in the PlayStation PayPal scam messages:
Sender Details
The sender email address is spoofed to appear like an official PayPal or PlayStation notification:
Addresses often include “service@paypal.com”, “playstation@email.sony.com”, or random names.
The name shown may say “PayPal”, “PlayStation”, “PlayStation Network”, etc.
But on closer inspection, the address is completely fake, using an invented email domain.
Subject Line
Subject lines always indicate an urgent payment update, such as:
Your PayPal PlayStation Invoice
Payment Failed for PlayStation Order
Update Your PlayStation PayPal Order
PayPal Invoice for PlayStation Purchase
Overdue: PlayStation Order Through PayPal
These subject lines aim to get your urgent attention if you’re awaiting a PlayStation console.
Email Body Content
The scam email bodies all follow a similar template. Here are some key traits:
PlayStation and PayPal logos prominently shown.
A 6-digit invoice number at the top to seem legitimate.
Your name, email, and partial account number displayed.
Details of a PlayStation order processed through PayPal that you didn’t actually place.
A payment deadline, usually 24-48 hours, to spur urgency.
Threat that failure to pay will result in PSN account suspension.
A U.S. toll-free number provided to call regarding the invoice.
Official-looking email footer and fine print.
This structured content plays on fear of losing your gaming account or access to an awaited PlayStation console. But awareness of the templates makes them easy to detect.
How the PlayStation PayPal Scam Unfolds
Now that you know the trademarks of the scam emails, let’s walk through the typical sequence of how the full PlayStation PayPal invoice scam unfolds:
Step 1: Fraudulent Email Received
You receive an email with the PlayStation and PayPal logos, an unknown invoice, threats of PSN suspension, and a support phone number. It’s aimed to worry you into hastily calling.
Step 2: Call Connects to Fake PlayStation Support Center
When you call the number, an offshore call center answers posing as PlayStation support. They cite the invoice and request remote access to your computer to supposedly fix security issues that allowed the unauthorized transaction.
Step 3: Scammers Gain Remote Access to Your Device
If you allow remote access, the criminals can install malware, steal data, and take control of your device. This grants them access to sensitive personal and financial information.
Step 4: Scammers Steal Your Money and Identity
Once inside your device and accounts, the scammers steal your money and your identity. They may siphon PayPal funds, use stolen credit cards to buy goods under your name that they resell for cash, or commit other forms of fraud and theft. The damage can be extensive.
Step 5: Ongoing Fraud and Account Lockouts
In the months following the scam, you may discover additional fraudulent charges made under your identity or have accounts locked due to suspicious activity. Clearing your name and recovering from fraud can be a lengthy process.
Avoid becoming a victim by recognizing the signs of fake PlayStation PayPal invoices before calling scammer phone numbers or providing any personal information.
10 Ways to Identify Fake PlayStation PayPal Invoices
Here are 10 clear indicators an invoice involving PlayStation and PayPal is a complete scam:
You aren’t expecting a PlayStation order or delivery.
The order contains extra items you didn’t purchase like games and accessories.
The email includes urgent threats of account suspension if you don’t pay.
There’s a short 1-2 day deadline to pay the invoice.
The sender email is not a real PlayStation or PayPal address.
You don’t recognize the 6-digit invoice number.
The total amount matches a real PlayStation model price like $499.
The email asks you to call a phone number about the invoice.
There are spelling/grammar errors uncommon for Sony or PayPal.
The linked phone number has bad reviews online mentioning scams.
If an invoice makes you uneasy, trust your instincts and scrutinize it fully before taking any action.
What to Do if You Receive a Fake PlayStation PayPal Invoice
If you get an email with a suspicious PlayStation invoice demanding payment through your PayPal account, take these steps:
Do not click any links or attachments in the email. They may contain malware.
Do not call the phone number under any circumstances. It will reach scammers.
Report the email as phishing/spam to your email provider.
Log in to your PayPal account to view notifications and invoices.
Contact PlayStation and PayPal customer service through official channels to confirm the legitimacy of any bills.
Monitor your PayPal account and credit reports for signs of unauthorized access or identity theft.
Change passwords on your important online accounts as a precaution.
With quick action, you can avoid becoming a victim. Remember, real companies don’t threaten urgent account suspension via email or phone. Verify bills through official account login.
What to Do if You Already Fell for the Scam
If you called the number and provided personal information or remote access, stay calm and take these steps:
Contact your bank and credit card companies to freeze accounts and cards. Watch for fraudulent charges.
Change passwords on all financial, email, social media and gaming accounts. Enable two-factor authentication where possible.
Scan devices for malware and completely wipe computers/phones that were accessed remotely.
Place fraud alerts and monitor your credit reports. Look for signs of new fraudulent accounts opened in your name.
Contact PlayStation to secure your PSN account if compromised and reset your password.
Report the scam to the FTC and your local police to help authorities stop the criminals.
Protecting Yourself from Fake PlayStation Invoices
The PlayStation invoice scam takes advantage of people anxiously awaiting the delivery of their new console. Here are some tips to avoid being deceived:
Never trust unsolicited emails: Sony will only contact you via the email associated with your PSN account. Verify anything suspicious.
Beware of threats and urgency: Real companies give reasonable timeframes to resolve issues, not 24 hour threats.
Don’t call random numbers: Only call official PlayStation support numbers listed on their real website.
Log in to PSN to view billing: Your real purchase and invoice history is visible in your PlayStation account.
Inspect sender details: Fake addresses like “playstation@email.sony.com” should raise alarms.
Look for poor grammar/spelling: Real PlayStation emails are written professionally and error-free.
With healthy skepticism, you can avoid being manipulated into calling scammers about fake PlayStation invoices. Verify any uncertainties directly through official PlayStation customer service before taking action.
Is Your Device Infected? Check for Malware
If your device is running slowly or acting suspicious, it may be infected with malware. Malwarebytes Anti-Malware Free is a great option for scanning your device and detecting potential malware or viruses. The free version can efficiently check for and remove many common infections.
Malwarebytes can run on Windows, Mac, and Android devices. Depending on which operating system is installed on the device you’re trying to run a Malwarebytes scan, please click on the tab below and follow the displayed steps.
Malwarebytes For WindowsMalwarebytes For MacMalwarebytes For Android
Scan your computer with Malwarebytes for Windows to remove malware
Malwarebytes stands out as one of the leading and widely-used anti-malware solutions for Windows, and for good reason. It effectively eradicates various types of malware that other programs often overlook, all at no cost to you. When it comes to disinfecting an infected device, Malwarebytes has consistently been a free and indispensable tool in the battle against malware. We highly recommend it for maintaining a clean and secure system.
Download Malwarebytes for Windows
You can download Malwarebytes by clicking the link below.
After the download is complete, locate the MBSetup file, typically found in your Downloads folder. Double-click on the MBSetup file to begin the installation of Malwarebytes on your computer. If a User Account Control pop-up appears, click “Yes” to continue the Malwarebytes installation.
Follow the On-Screen Prompts to Install Malwarebytes
When the Malwarebytes installation begins, the setup wizard will guide you through the process.
You’ll first be prompted to choose the type of computer you’re installing the program on—select either “Personal Computer” or “Work Computer” as appropriate, then click on Next.
Malwarebytes will now begin the installation process on your device.
When the Malwarebytes installation is complete, the program will automatically open to the “Welcome to Malwarebytes” screen.
On the final screen, simply click on the Open Malwarebytes option to start the program.
Enable “Rootkit scanning”.
Malwarebytes Anti-Malware will now start, and you will see the main screen as shown below. To maximize Malwarebytes’ ability to detect malware and unwanted programs, we need to enable rootkit scanning. Click on the “Settings” gear icon located on the left of the screen to access the general settings section.
In the settings menu, enable the “Scan for rootkits” option by clicking the toggle switch until it turns blue.
Now that you have enabled rootkit scanning, click on the “Dashboard” button in the left pane to get back to the main screen.
Perform a Scan with Malwarebytes.
To start a scan, click the Scan button. Malwarebytes will automatically update its antivirus database and begin scanning your computer for malicious programs.
Wait for the Malwarebytes scan to complete.
Malwarebytes will now scan your computer for browser hijackers and other malicious programs. This process can take a few minutes, so we suggest you do something else and periodically check the status of the scan to see when it is finished.
Quarantine detected malware
Once the Malwarebytes scan is complete, it will display a list of detected malware, adware, and potentially unwanted programs. To effectively remove these threats, click the “Quarantine” button.
Malwarebytes will now delete all of the files and registry keys and add them to the program’s quarantine.
Restart your computer.
When removing files, Malwarebytes may require a reboot to fully eliminate some threats. If you see a message indicating that a reboot is needed, please allow it. Once your computer has restarted and you are logged back in, you can continue with the remaining steps.
Your computer should now be free of trojans, adware, browser hijackers, and other malware.
If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow one of the steps:
Scan your computer with Malwarebytes for Mac to remove malware
Malwarebytes for Mac is an on-demand scanner that can destroy many types of malware that other software tends to miss without costing you absolutely anything. When it comes to cleaning up an infected device, Malwarebytes has always been free, and we recommend it as an essential tool in the fight against malware.
Download Malwarebytes for Mac.
You can download Malwarebytes for Mac by clicking the link below.
When Malwarebytes has finished downloading, double-click on the setup file to install Malwarebytes on your computer. In most cases, downloaded files are saved to the Downloads folder.
Follow the on-screen prompts to install Malwarebytes.
When the Malwarebytes installation begins, you will see the Malwarebytes for Mac Installer which will guide you through the installation process. Click “Continue“, then keep following the prompts to continue with the installation process.
When your Malwarebytes installation completes, the program opens to the Welcome to Malwarebytes screen. Click the “Get started” button.
Select “Personal Computer” or “Work Computer”.
The Malwarebytes Welcome screen will first ask you what type of computer are you installing this program, click either Personal Computer or Work Computer.
Click on “Scan”.
To scan your computer with Malwarebytes, click on the “Scan” button. Malwarebytes for Mac will automatically update the antivirus database and start scanning your computer for malware.
Wait for the Malwarebytes scan to complete.
Malwarebytes will scan your computer for adware, browser hijackers, and other malicious programs. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
Click on “Quarantine”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes has detected. To remove the malware that Malwarebytes has found, click on the “Quarantine” button.
Restart computer.
Malwarebytes will now remove all the malicious files that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your computer.
Your Mac should now be free of adware, browser hijackers, and other malware.
If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future. If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.
Scan your phone with Malwarebytes for Android to remove malware
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.
When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options. This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue. Tap on “Got it” to proceed to the next step. Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue. Tap on “Allow” to permit Malwarebytes to access the files on your phone.
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.
Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
Your phone should now be free of adware, browser hijackers, and other malware.
If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future. If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
Frequently Asked Questions About the PlayStation PayPal Invoice Scam
1. How can I tell if a PlayStation PayPal invoice is fake?
Fake PlayStation invoices often come from non-official email addresses and contain urgent threats of PSN suspension if unpaid. Real Sony invoices allow reasonable timeframes to address issues. Fake bills also show unfamiliar transaction details not visible in your PayPal account activity.
2. What happens if I call the phone number on a fake invoice?
The numbers in scam PlayStation emails lead to offshore call centers where criminals posing as Sony support will request remote access to your computer to steal personal data and money from your accounts. Never call numbers provided in suspicious emails.
3. Why do scammers threaten to suspend my PSN account?
Scammers use threats of immediate account suspension to spur victims into urgently calling the number and complying with demands to avoid disruption to gaming. But real PlayStation only suspends accounts after multiple ignored notifications.
4. How can I report fake PlayStation PayPal invoices?
Do not click any links in scam emails. Report them as phishing to your email provider. Forward scam invoices to PayPal at spoof@paypal.com and to PlayStation customer support. File complaints with the FTC and police about the scam.
5. What precautions should I take if I provided scammers remote access?
If you allowed scammers remote access, immediately change all account passwords and freeze financial accounts. Scan devices for malware, wipe any remotely accessed devices, and place fraud alerts to prevent identity theft.
6. How can I avoid falling for the PlayStation PayPal invoice scam?
Always directly login to PayPal and PSN to view billing notices instead of trusting emails. Analyze sender details of emails and never call random phone numbers in suspicious messages. Also watch for poor grammar/spelling and urgent threats in scam invoices.
7. Can PayPal be used to pay for PlayStation products?
Yes, PayPal can be safely used to make real PlayStation purchases. But always login directly to PayPal and PlayStation Network to view legitimate invoices. Never trust emails claiming PlayStation orders were processed through your PayPal account.
8. Where can I find the official PlayStation customer support number?
Find the legitimate PlayStation customer service number listed on the official playstation.com website. Do not call random numbers provided in suspicious emails claiming to be from Sony.
9. What should I do if my PSN account gets suspended?
If your real PSN account gets suspended, login to PlayStation Network to check the notification instructions. Suspensions could be from policy violations or hacking concerns. Contact official PlayStation customer service to resolve any account limitations.
10. How can I safely buy a PlayStation console?
Only buy PlayStation consoles and products through authorized retailers like Amazon, Best Buy, GameStop, and other major chains, or directly through official Sony channels. Avoid unauthorized resellers.
In Summary
The PlayStation invoice payment scam shows that even reputable brands like Sony can be impersonated if you aren’t careful. But by recognizing the deceitful patterns in the fraudulent emails and calls, you can avoid becoming another victim. If you receive a questionable invoice, do not call the provided number or panic into immediate payment. Verify the situation by logging into your PlayStation Network account and contacting official customer service channels. Keep your gaming focus on entertainment rather than falling prey to scams.
How to Stay Safe Online
Here are 10 basic security tips to help you avoid malware and protect your device:
Use a good antivirus and keep it up-to-date.
It's essential to use a good quality antivirus and keep it up-to-date to stay ahead of the latest cyber threats. We are huge fans of Malwarebytes Premium and use it on all of our devices, including Windows and Mac computers as well as our mobile devices. Malwarebytes sits beside your traditional antivirus, filling in any gaps in its defenses, and providing extra protection against sneakier security threats.
Keep software and operating systems up-to-date.
Keep your operating system and apps up to date. Whenever an update is released for your device, download and install it right away. These updates often include security fixes, vulnerability patches, and other necessary maintenance.
Be careful when installing programs and apps.
Pay close attention to installation screens and license agreements when installing software. Custom or advanced installation options will often disclose any third-party software that is also being installed. Take great care in every stage of the process and make sure you know what it is you're agreeing to before you click "Next."
Install an ad blocker.
Use a browser-based content blocker, like AdGuard. Content blockers help stop malicious ads, Trojans, phishing, and other undesirable content that an antivirus product alone may not stop.
Be careful what you download.
A top goal of cybercriminals is to trick you into downloading malware—programs or apps that carry malware or try to steal information. This malware can be disguised as an app: anything from a popular game to something that checks traffic or the weather.
Be alert for people trying to trick you.
Whether it's your email, phone, messenger, or other applications, always be alert and on guard for someone trying to trick you into clicking on links or replying to messages. Remember that it's easy to spoof phone numbers, so a familiar name or number doesn't make messages more trustworthy.
Back up your data.
Back up your data frequently and check that your backup data can be restored. You can do this manually on an external HDD/USB stick, or automatically using backup software. This is also the best way to counter ransomware. Never connect the backup drive to a computer if you suspect that the computer is infected with malware.
Choose strong passwords.
Use strong and unique passwords for each of your accounts. Avoid using personal information or easily guessable words in your passwords. Enable two-factor authentication (2FA) on your accounts whenever possible.
Be careful where you click.
Be cautious when clicking on links or downloading attachments from unknown sources. These could potentially contain malware or phishing scams.
Don't use pirated software.
Avoid using Peer-to-Peer (P2P) file-sharing programs, keygens, cracks, and other pirated software that can often compromise your data, privacy, or both.
To avoid potential dangers on the internet, it's important to follow these 10 basic safety rules. By doing so, you can protect yourself from many of the unpleasant surprises that can arise when using the web.
Meet Thomas Orsolya
Thomas is an expert at uncovering scams and providing in-depth reporting on cyber threats and online fraud. As an editor, he is dedicated to keeping readers informed on the latest developments in cybersecurity and tech.