The email lands with a jolt of good news: "Congratulations! Your prize of $2,500.00 has been credited to your PayPal account — PENDING." There's a blue button, a case number, maybe a countdown. It looks like money is already sitting there with your name on it. It isn't. This is one of the oldest sweepstakes-scam tricks wearing a payment-processor costume, and the whole illusion rests on one lie: that a balance you can see is a balance you can spend. 💰
Real PayPal never gates a payout behind a fee
Here's the rule that collapses the entire scam: PayPal does not charge you to receive money. When someone sends you funds, they land in your balance and you withdraw them — no "release fee," no "insurance," no "currency-conversion deposit," no gift-card handshake. If any email tells you to pay money to unlock money you supposedly already won, you are looking at fraud, full stop. Scammers love this framing because a $35 or $99 "processing fee" feels tiny against a $2,500 prize, and once you send it — usually by Zelle, Cash App, wire, or gift cards, all hard to reverse — it's gone.
The fake "pending balance" is pure stagecraft. A forged email can say $2,500 is pending all day; that number lives in an image or some HTML, not in a real account. The tell is the direction of the money. Legitimate winnings flow to you and cost you nothing. A message that needs a payment, a "verification deposit," or your card number before the prize can move describes a transaction that only benefits the sender. No real sweepstakes and no real payment processor works that way.
Read the sender and the link, not the logo
A convincing PayPal logo proves nothing — anyone can paste one in. What's much harder to fake is the sender domain and the real destination of that shiny button. Check the address the email came from: genuine PayPal messages come from @paypal.com, not @paypal-secure-team.com, @paypaI.com (a capital I posing as an l), or some Gmail address. On a phone, tap the sender name to expand the full address first. Better still, PayPal addresses real customers by their first and last name; scam blasts open with "Dear User," "Dear Customer," or your bare email prefix, because they mailed a hundred thousand people at once.
Then check the button — on desktop, hover and read the URL in the corner; on mobile, press and hold to preview. A "Log in to release funds" link pointing anywhere other than paypal.com is a phishing hook built to grab your password on a lookalike page. That login step is the email's actual goal: not to give you $2,500, but to harvest your credentials and drain the real account behind them. When in doubt, ignore every link, type paypal.com by hand or open the app, and check your balance directly. If there's no prize there, there's no prize.
What to do when one arrives
Don't reply, don't click, and don't call any number the email provides — the "support line" rings the scammers. Forward the message to phishing@paypal.com, then delete it. If you already entered your PayPal password on a linked page, change it immediately on the real site, turn on two-factor authentication, and scan your account for unauthorized activity. Then change that password anywhere you reused it, because credential-stuffing bots will try it on your email and bank within hours.
Expect a follow-up, too. Once you engage even a little, scammers often escalate to a call or text posing as "PayPal fraud protection," and the goal shifts to talking you through a fake "refund reversal" or reading you a six-digit code — never share that code. Report the scheme to the FTC at reportfraud.ftc.gov and, if you lost money, to the FBI's Internet Crime Complaint Center at ic3.gov. 🛡️
No legitimate prize ever asks you to pay a fee to collect it — if money has to leave your pocket first, walk away.