About 5 minutes ago I received an email of payment verification from transaction@paypal.com, addressed to my exact email acocunt, not saying "dear user", saying: "This email confirms that you have paid Astalavista Group GmbH (info@astalavistae.net) $39.00 USD using PayPal.". It looked like an official email completely, too. Like an idiot, I clicked the link in the email, logged in because I thought maybe I had accidentally paid that company (which I never heard of). Luckily I looked at the full URL, and changed my password on the real PayPal site quickly.
Cliffs: I'm an idiot
Fake PayPal site (remove the dash from the link):
http://www.pay-pal.com.scrwb.us/icmd=_login-submit.htm
Cliffs: I'm an idiot
Fake PayPal site (remove the dash from the link):
http://www.pay-pal.com.scrwb.us/icmd=_login-submit.htm
