I'm posting this in General Discussion for now since I know many don't peruse Computer Talk at unless they have computer problems (or they're just geeks like Howie and me).
I received a phishing attempt from someone pretending to be from PayPal today. That's nothing new, but this one had a little different slant to it and may dupe people who aren't used to fielding these fraudulent e-mails. here's the text from the e-mail I received. I've put spaces in the relevant URL's so they don't automatically hyperlink.
You have added dechukiat @ yahoo. com as a new email address for
your PayPal account.
If you did not authorize this change or if you need assistance
with your account, please contact PayPal customer service at:
htt ps: // w ww. paypal. com/ us/wf/f=ap_email
Thank you for using PayPal!
The PayPal Team
Please do not reply to this e-mail. Mail sent to this address cannot
be answered. For assistance, log in to your PayPal account and choose
the "Help" link in the header of any page.
-----------------------------------------------------------------
PROTECT YOUR PASSWORD
NEVER give your password to anyone and ONLY log in at
htt ps:// ww w.paypal. com/. Protect yourself against fraudulent websites
by opening a new web browser (e.g. Internet Explorer or Netscape)
and typing in the PayPal URL every time you log in to your account.
-----------------------------------------------------------------
PayPal Email ID PP105>
It looked official enough to fool someone not on the lookout for fraud mails, but one thing I noticed right off - aside from the fact that my name was not anywhere in the e-mail - was the URL they posted. While it displays as
htt ps: // ww w. paypal. com /us/wf/f=ap_email (spaces added), what that link actually points to is something else altogether: http: // ww w.google. co.uk/url?sa=U&start=4&q= http:// 211.21.82.91/ java/index.php
They're routing access to their page through Google. Looks like there's javascript involved, possibly something which preys on security holes in vulnerable systems. In a word: Don't go there!
Just wanted to post this as a heads-up in case you've not seen these latest phishing mails.
