During the past year, Let's Encrypt has issued a total of 15,270 SSL certificates that contained the word "PayPal" in the domain name or the certificate identity.
“Of these, approximately 14,766 (96.7%) were issued for domains that hosted phishing sites, according to an analysis carried out on a small sample of 1,000 domains, by Vincent Lynch, encryption expert for The SSL Store.
His findings reveal how phishers gradually tested if they could get, deploy, and keep hold of Let's Encrypt certificates for malicious websites.
Around October and November last year, the floodgates opened, and the number of Let's Encrypt SSL certificates issued for PayPal-themed phishing sites increased in a dramatic fashion.”
The article contains useful insight and images which show a fake PayPal site vs a genuine one. Although the fake sites will usually be spotted and taken down within a couple of days, this is often enough time to do some damage.
- SECURITY EXPERT
- Talking Point
- Posted On



