Scammers are using data from outdated plugins to send convincing payout notifications for tiny amounts like A$0.70
Published: March 2026 | Cybercrim.com
If you’ve received a Stripe payout notification you weren’t expecting — don’t click any links. Check your Stripe dashboard first.
If the transaction doesn’t exist on your account, the email isn’t about you — but it may still be worth reporting. This article explains what’s going on, why the email looks so convincing, and exactly what to do.

The Fastest Way to Know If This Is Real
Check your Stripe dashboard. That’s it.
Open a new browser tab, go to dashboard.stripe.com, log in, and look at your Payouts section. If the payout mentioned in the email doesn’t appear in your account – then the email isn’t about a transaction on your account. That’s the clearest and simplest red flag.
In the case we investigated, the email referenced a specific Stripe account called “Blog Sites” with a payout of A$0.70. When the recipient checked their own Stripe dashboard, there were no matching transactions at all. The account ID, the payout ID, and the bank reference in the email didn’t belong to them.
✅ The simplest check
- Don’t click any links in the email
- Open dashboard.stripe.com in a new tab
- Check your Payouts section
- If the payout isn’t there, the email isn’t about your account
So What’s Actually Happening?
When we dug into the email, we found something that made this more complicated than a straightforward phishing attempt. The “Track payout” link didn’t go to a fake website. It pointed to a genuine Stripe email-tracking subdomain (59.email.stripe.com) that redirects to the real Stripe dashboard.
But when the recipient checked their own dashboard, the payout didn’t exist. No matching transaction, no matching account name, nothing.
That means this email is a notification from someone else’s Stripe account – and it was sent to the wrong person.
There are two likely explanations for how this happens:
Scenario A – A Compromised Stripe Account Is Being Used for Card Testing
Someone has gained access to a different WordPress site owner’s Stripe account – likely through a vulnerable or outdated payment plugin that exposed their API keys. The scammers are using that compromised account to process tiny transactions with stolen credit card numbers to test which cards are still active.
Stripe then generates genuine payout notifications for these small amounts. Your email address may have ended up associated with that compromised account, or it may have been harvested from the same plugin vulnerability and added to the account’s notification list.
The A$0.70 amount is a textbook card-testing figure – too small to trigger bank alerts, but enough to confirm whether a stolen card number works.
Scenario B – The Email Is Using Real Stripe Infrastructure to Phish You
Even though the initial link points to a genuine Stripe domain, the redirect chain could still funnel you through a credential capture step. If the link ultimately asks you to “log in to view this payout,” you might enter your real Stripe credentials on what appears to be a Stripe page – but is actually a lookalike designed to harvest them.
The fact that the payout doesn’t exist on your account wouldn’t matter to the scammers – they already have what they need the moment you type in your login details.
In both cases, the email references an account that isn’t yours and a transaction you didn’t make. That’s the dead giveaway.
| Scenario A — Card Testing | Scenario B — Phishing |
|---|---|
| Link goes to real stripe.com | Link may redirect to a fake login |
| Notification is genuine | Goal is to steal your credentials |
| Someone else’s account is compromised | Email crafted to look routine |
| Stolen cards being validated | Real Stripe URLs used as cover |
| Your email was associated by mistake | Account takeover risk if you log in |
| Report to help Stripe shut it down | Delete and report immediately |
What’s Suspicious About This Email
Even though parts of this email appear to be backed by real Stripe infrastructure, several things should raise your guard.
The payout doesn’t exist on your account
This is the biggest and most obvious red flag. If you check your Stripe dashboard and the transaction isn’t there, the email is either about someone else’s account or entirely fabricated. Either way, it has nothing to do with you – and clicking through serves no purpose other than putting you at risk.
Hidden invisible characters in the email
The area between the subject line and the body is packed with over a hundred invisible Unicode characters – Combining Grapheme Joiners (U+034F) and soft hyphens (U+00AD). These pad out the inbox preview text and help the email bypass spam filters by breaking up content that automated tools try to pattern-match. While some legitimate email platforms insert tracking characters, this volume of invisible padding is unusual.
Excessive blank space in the body
The email has large gaps between sections, likely created with empty HTML table cells. This can make it harder for email security tools to analyse the full message. Genuine Stripe emails are compact and cleanly formatted.
A very small payout amount
A$0.70 is a textbook card-testing figure. Tiny amounts don’t trigger bank alerts and look like routine micro-transactions. Whether this is real card testing or a phishing lure, the small number is designed to feel unremarkable – just interesting enough to make you click.
⚠️ Red flags at a glance
- The payout doesn’t exist on your Stripe account
- Invisible Unicode characters hidden in the preheader text
- Excessive blank spacing between content sections
- Unusually small payout amount (A$0.70)
Why This Email Looks Completely Legitimate
This is what makes this scam particularly hard to spot. It doesn’t rely on urgency, threats, or poor spelling. It looks like a boring, routine notification – and in some cases, parts of it genuinely are from Stripe.
- It copies Stripe’s real email layout. The formatting, fonts, and structure closely match genuine payout notifications.
- It uses correct Stripe ID formats. The payout ID starts with “po_” and the account ID starts with “acct_” – both genuine Stripe conventions.
- The link can point to real Stripe servers. In the case we examined, the “Track payout” URL went to 59.email.stripe.com – a genuine Stripe click-tracking subdomain. This is the single hardest detail to spot, because it genuinely is a Stripe link.
- It includes Stripe’s real corporate address. The footer lists Stripe’s actual headquarters at 354 Oyster Point Blvd, South San Francisco.
- It references a masked bank account. The “To: MET ••••1131” format matches exactly how Stripe displays bank details in real notifications.
- The support text sounds genuinely helpful. The paragraph about waiting 5 business days and contacting your bank is written in the same tone and language Stripe uses in its real emails.
- There are no spelling or grammar mistakes. Unlike many phishing emails, this one is clean and well-written.
The key takeaway: you can’t always tell if an email is a scam just by checking the link or looking for typos. In this case, the only reliable way to verify it was to check the Stripe dashboard directly. If the transaction isn’t there, it’s not yours — regardless of how polished the email looks.
How to Verify Any Stripe Email
Here’s a step-by-step process you can follow every time you receive a Stripe notification you’re not sure about.
1. Don’t click anything in the email
Always the safest first step. Open a new browser tab instead.
2. Go directly to your Stripe dashboard
Type dashboard.stripe.com into your browser, log in, and check the Payouts section. If the payout exists, check whether the details match and whether you recognise the transaction. If it doesn’t exist, the email is either fake or about someone else’s account.
3. Check the sender’s email address
Click on the sender’s name to reveal the full address. Genuine Stripe emails come from addresses ending in @stripe.com. Watch for lookalike domains such as @stripe-support.com or @striipe.com.
4. Hover over the link to preview the URL
On a computer, hover over the button without clicking. Your email client should show the destination URL. Legitimate Stripe links point to stripe.com or subdomains like email.stripe.com. But remember – even a real Stripe link doesn’t mean the email is relevant to you. Always cross-check with your dashboard.
5. Look for email authentication markers
Some email clients display a verified brand logo (using BIMI) next to authentic emails. In Gmail, you can also click the three dots and select “Show original” to check SPF, DKIM, and DMARC results. If these all pass, the email was sent from Stripe’s servers – but that still only confirms the email is from Stripe, not that the transaction is yours.
✅ Verification checklist
- Don’t click any links in the email
- Open dashboard.stripe.com and check Payouts
- Confirm the sender ends in @stripe.com
- Hover over buttons to preview destination URLs
- Even if the link is real, check your dashboard anyway
- No matching transaction = not your concern (but report it)
How This Happens — The WordPress Connection
Both scenarios appear to be connected to a common starting point – WordPress sites running vulnerable payment plugins that expose Stripe account data.
Outdated plugins can leak Stripe details
Many WordPress websites use plugins to connect to Stripe – such as WooCommerce Stripe Gateway, WPForms, or membership plugins. When these aren’t updated, they can contain security flaws that expose Stripe account IDs, API keys, email addresses, and payout configuration details to anyone who knows where to look.
Several major vulnerabilities in WordPress payment plugins have been publicly documented in recent years. These flaws can allow unauthenticated access to order data, payment details, and Stripe account information.
Leaked API keys enable card testing
If a Stripe secret API key is exposed, a scammer can process transactions through that account without ever logging in. They run small charges using stolen card numbers to test which cards are active. Stripe sends genuine payout notifications because, from Stripe’s perspective, the transactions look normal.
Harvested data enables phishing
In other cases, the data from vulnerable plugins is used to craft convincing phishing emails. Real account IDs and Stripe formatting are combined with fake links to build emails that are extremely hard to distinguish from genuine ones.
🔍 Worth knowing about malicious plugins
Security researchers have identified malicious WordPress plugins — such as one called PhishWP — that are purpose-built to create fake Stripe payment pages on compromised websites. These plugins capture card details in real time and send them directly to attackers. This is a separate but related threat that reinforces why keeping your WordPress plugins updated and removing any you don’t recognise is essential.
What You Should Do
If there are no matching transactions on your Stripe account
This is the most common scenario. The email references someone else’s account and the payout has nothing to do with you. Here’s what to do:
- Don’t click any links in the email. Even if the initial link points to Stripe, the redirect chain could include a credential capture step.
- Forward the full email to [email protected]. This is Stripe’s dedicated address for reporting suspicious emails. Forward the original (don’t screenshot it) so Stripe can inspect the headers and link structure. You can also send it to [email protected].
- Mark the email as phishing or spam in your email client. This helps your provider filter similar emails in the future.
- Check that your own Stripe account is secure. Even though the payout isn’t yours, the fact that you received the email means your email address may have been harvested. Confirm 2FA is enabled and review your API keys.
- If you run a WordPress site, update your plugins. Your email address may have been exposed through a vulnerable plugin on your own site or one you’re associated with.
If you find unexpected transactions on your Stripe account
This is more serious. It means someone is actively using your account.
- Revoke and regenerate your API keys immediately from Developers > API Keys in your Stripe dashboard. This cuts off unauthorised access.
- Check for unfamiliar connected accounts under Settings > Connect. Scammers sometimes create connected accounts to redirect funds.
- Verify your payout destination hasn’t been changed and that no new bank accounts or payout methods have been added.
- Refund any suspicious transactions. This can help prevent chargebacks. If the charges used stolen cards, the cardholders will eventually dispute them – and you could be liable for fees if you haven’t refunded.
- Contact Stripe Support to report the unauthorised activity.
- Set up Stripe Radar rules to block payments in unexpected currencies, amounts under $1, or from regions that don’t match your business.
If you clicked the link and entered your login details
- Change your Stripe password immediately.
- Enable two-factor authentication (2FA) if it isn’t already active.
- Review your account for unfamiliar connected accounts, payout changes, or unrecognised activity.
- Revoke and regenerate your API keys.
- Contact Stripe Support to report the compromise.
How to Report This
Even if you’re not personally at risk, reporting helps Stripe investigate the compromised account and protects other people who may have received the same email.
Report to Stripe
- Forward the original email to [email protected]. Don’t modify or screenshot it – forward the original so Stripe can inspect the full headers and link structure.
- You can also send it to [email protected] if you want a response from their team.
- For formal complaints, use the form at stripe.com/complaints.
Report to authorities
- Australia: Report to Scamwatch at scamwatch.gov.au and to ReportCyber at cyber.gov.au
- UK: Report to Action Fraud at actionfraud.police.uk and forward the email to [email protected]
- US: Report to the FTC at reportfraud.ftc.gov and forward to [email protected]
- Canada: Report to the Canadian Anti-Fraud Centre at antifraudcentre-centreantifraude.ca
Protecting Your WordPress Site
If you run a WordPress site that connects to Stripe, these steps can reduce your exposure:
- Update all plugins regularly, especially payment and membership plugins.
- Remove plugins you’re not actively using. Inactive plugins with known vulnerabilities can still be exploited.
- Regenerate your Stripe API keys periodically and immediately if you suspect any compromise.
- Enable Stripe Radar and configure rules to block suspicious transactions.
- Require full card verification (CVV, billing address, email) for all transactions.
- Use a WordPress security plugin (such as Wordfence or Sucuri) to monitor for vulnerabilities and suspicious activity.
The Bottom Line
The strongest protection against this scam is the simplest one: check your Stripe dashboard. If the payout isn’t there, the email isn’t about you.
Even if the link looks real and the email is well-written, your dashboard is the only source of truth. Don’t click links to verify — log in directly.
If you do find unexpected transactions, revoke your API keys, refund the charges, and contact Stripe immediately. If you don’t find anything, forward the email to [email protected] and move on.
These emails are designed to look so routine that you don’t think twice. The fact that you stopped to check is exactly the right instinct.
Cybercrim.com provides general information about online threats and scams. This article is for awareness purposes only and does not constitute legal, financial, or technical advice. If you believe you’ve been affected by a scam, contact the relevant authorities and service providers directly.