I received an email from an eBay member, using the eBay message system. If you’re not familiar with how it works, you don’t reply directly from your email, but you are required to sign in to eBay, which you do by clicking on a button that says “Respond to This Question in My Messagesâ€?.
Here’s the text of the email from a user supposedly named “sydatkinson�
Hello,
The package you sent me didnt arrive yet. Respond ASAP or ill report you!
There was nothing suspicious looking about the email other than the guy is acting like an idiot, and I had been late on a few packages after the holidays, so I assumed this was one of them. I flipped through my paperwork and didn’t see any transactions from this him, and he didn’t give me any other information to tell me which auction item he was referring to, so clicked on the “Respond Now” button.
I proceeded to type in my username and password at which point, I received an error that Firefox was not allowing cookies from this site and I needed to turn them on. Huh? Oh, the hell with that. So instead I clicked on my bookmarked link to eBay and signed in the usual way so I could respond to his question and ask him for more details.
There were several older messages, but none from this guy. Hmm. That’s strange.
WAIT A MINUTE!
I clicked to show the source code for the email to confirm my suspicions, and found this:
Received: from server5.freeonlinegames.com
…and the button I clicked on (and neglected to confirm where it was sending me) went here:
http://mail.eturn.com.tw/~lu/signin.ebay.com…etc…etc…
SHIT!
As fast as I could click, I went back to the REAL eBay, immediately changed my password, since I had just typed it into a fake site, and then went into Paypal and changed that too, just for good measure.
GODDAMN SPAM AND I FELL FOR IT!