# LiveChat Abuse: Phishing Campaign Targets PayPal and Amazon Users

> Threat actors are leveraging legitimate LiveChat platforms to impersonate PayPal and Amazon support agents, stealing credit card and personal data.

- Published: 2026-03-16T16:30:10.000Z
- Severity: medium
- Category: Threat Intel
- Tags: Phishing, Livechat, Social Engineering, Paypal, Amazon
- Author: Runtime Rebel Intel
- Primary source: https://www.darkreading.com/threat-intelligence/attackers-livechat-phish-credit-card-personal-data
- Canonical: https://runtimerebel.com/blog/livechat-abuse-phishing-campaign-targets-paypal-and-amazon-users

## Key points

- Attackers impersonate PayPal and Amazon support agents to steal sensitive financial and personal identification data from customers via live chat windows.
- Web-based customer service platforms and users interacting with support widgets on fraudulent or compromised websites are primarily at risk.
- Implement strict domain verification for support tools and educate users on identifying suspicious link-sharing during active live chat sessions.

According to [Dark Reading](https://www.darkreading.com/threat-intelligence/attackers-livechat-phish-credit-card-personal-data), threat actors are increasingly leveraging legitimate customer support platforms to conduct highly effective [Phishing](/glossary#phishing) operations. By abusing the inherent trust users place in official-looking chat widgets, attackers are successfully harvesting credit card information and personal data from users of major brands like PayPal and Amazon. This campaign highlights a specific shift in [TTP](/glossary#ttp) sets, moving away from traditional email-based lures toward real-time social engineering within a trusted web environment.

## Analysis of the Phishing Campaign Targeting PayPal Customers
The primary mechanism of this attack involves the deployment of fraudulent or compromised LiveChat instances. Unlike traditional attacks that rely on static landing pages, this [phishing campaign targeting PayPal customers](https://www.darkreading.com/threat-intelligence/attackers-livechat-phish-credit-card-personal-data) utilizes the interactive nature of live support. Users seeking assistance are greeted by what appears to be a legitimate representative. 

The attacker-controlled agent initiates a conversation that mimics standard support protocols. Once rapport is established, the agent requests the user to "verify" their account or "process a refund" by clicking a link provided directly within the chat window. This link leads to a sophisticated credential harvesting page designed to capture names, addresses, and full credit card details. Because the interaction occurs within a known support framework, victims are less likely to exercise the same level of caution they might with an unsolicited email.

### Exploiting Trust in Live Support Frameworks
The technical sophistication of this threat lies in its infrastructure. Attackers may use trial accounts on legitimate live chat platforms or compromise the [Supply Chain Attack](/glossary#supply-chain-attack) of smaller e-commerce sites to host these malicious widgets. By embedding these tools on look-alike domains (typosquatting), the threat actors create a seamless experience for the target. 

From a [MITRE ATT&CK](/glossary#mitre-att-ck) perspective, this campaign utilizes T1566.003 (Phishing: Actionable Link) and T1204.001 (User Execution: Malicious Link). The use of real-time interaction also allows attackers to bypass some automated [EDR](/glossary#edr) and email filtering solutions, as the malicious activity occurs over HTTPS within an authenticated or trusted third-party chat session. This method effectively masks the [C2](/glossary#c2) communication within standard web traffic directed toward reputable service providers.

## Mitigation for Support Chat Social Engineering
Defenders must adopt a defensive posture that addresses the social engineering aspect of these attacks while hardening the technical environment. Organizations should audit their use of third-party chat scripts and ensure that only authorized, domain-locked widgets are active on their web properties.

*   **Domain Monitoring:** Organizations should monitor for typosquatting domains that might host fraudulent support portals or use the brand's likeness in conjunction with chat services.
*   **User Training:** Security awareness programs must evolve to include training on how to verify the authenticity of a support representative, emphasizing that legitimate services like PayPal will rarely ask for full credit card numbers via a chat interface.
*   **Integrity Checks:** Regularly verify the integrity of the JavaScript files loaded by support widgets to prevent unauthorized modifications that could redirect chat traffic.

### How to Detect LiveChat Phishing Attacks
To improve visibility, a [SOC](/glossary#soc) should integrate web logs with their [SIEM](/glossary#siem) to identify unusual traffic patterns directed toward known chat platform APIs from unauthorized domains. When researching [how to detect LiveChat phishing attacks](https://www.darkreading.com/threat-intelligence/attackers-livechat-phish-credit-card-personal-data), analysts should focus on outbound connections to known chat service subdomains originating from unexpected areas of the corporate network. Analyzing [IoC](/glossary#ioc) data, such as specific URLs or patterns in the chat transcripts (if accessible via API), can help identify automated bots or scripts used by attackers to scale these operations. Implementing [Zero Trust](/glossary#zero-trust) principles can also limit the potential damage if an attacker attempts [Lateral Movement](/glossary#lateral-movement) after obtaining initial user credentials.

**Related:** [ClickFix Attack: Windows Terminal Used for Detection Evasion](/blog/clickfix-attack-windows-terminal-used-for-detection-evasion), [AI-Enabled Threats: Model Extraction, APT Phishing, & Malware Evolution](/blog/ai-enabled-threats-model-extraction-apt-phishing-malware-evolution)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/livechat-abuse-phishing-campaign-targets-paypal-and-amazon-users
