I have just received an email from service@paypal.com (yup, that's the domain in the email headers, this isn't some spoofed name).
The email is an obvious phishing attempt, referring to an address change and order I never made. Logging into my PayPal account, everything is unchanged and fine.
What I am surprised by is that anyone managed to send an email from service@paypal.com? How is that possible without their DNS being compromised somehow?
Someone on Reddit[0] has reported the same and I am wondering if anyone here has noticed / whether anyone here works at Paypal and needs to hear about this.
[0] https://old.reddit.com/r/paypal/comments/1ihs0ls/getting_tons_of_phishing_emails_from_verified/
I'm not defending PayPal here, but people can also arbitrarily send a fraudulent invoice to you in email, or via the physical mail, or call you on the phone as well. Fraud of this sort is by no means an issue exclusive to PayPal.
You can't assume that all communications you receive from PayPal are legitimate requests, in the same way you can't assume that all letters or phone calls or text messages you receive are legitimate requests.