I’ve been had

Oh my god. I’m so stupid.

I got an email from Gmail@gmail.com and I clicked a link that looked like a plain text URL that Gmail had turned into a link. It took me to the Gmail sign-in page (complete with ticking-over free space counter). It was only after I’d signed in that I looked at the addressbar. redscream.com != google.com. So I ran back to Gmail and changed my password as fast as I could.

Bloody hell. That’s the first time I’ve been caught out by phishing mail. I feel so stupid.

Here’s what I told Google:

I got a phishing mail from “Gmail@gmail.com” today. I’m ashamed to say I fell for it because I didn’t look at the address bar until it was too late (but I changed my password immediately so it’s okay).

It contained a link that had a Gmail URL in the content but a different URL in the href (it looked like it was a plaintext URL that Gmail had turned into a link). I suggest that you highlight such links to help people recognise phishing attempts.

I might see if I can write a Greasemonkey script to do the same thing in the meantime.

One Response to “I’ve been had”

  1. Niall Fleming Says:

    see your first mistake was opening anything from gmail@gmail.com….

Leave a Reply

You must be logged in to post a comment.