It is not uncommon these days to receive an email from a well-known, legitimate company alerting you to the fact that a recent online transaction had a problem. The email informs you that you will need to login to their website using your user name and password in order to rectify the problem. Since the email seems to be legitimate and the "from field" indicates that the email in fact, comes from the company, you click the link and login to your account.
You find out much later, unfortunately, that the website is bogus. It was created with the sole intent to steal your personal information. You have just been a victim of a "phishing" expedition.
The intent of phishing (pronounced as "fishing") is to lure unsuspecting individuals into revealing personal information such as user names and passwords to their online bank accounts and other sensitive sites. This is usually done by sending an email to a recipient that resembles an email from a legitimate business. The intent of the phisher is to fool the recipient into surrendering their private information, and ultimately steal their identity or other private information.
An email that is phishing for information is usually difficult to spot. The email that you receive will have been carefully crafted to appear to be from a legitimate company, like a major bank. The "From field" of the e-mail will probably have the address of the company that it is purporting to be. The clickable link even appears to take you to the company's website. However, this is a completely illegitimate site created to look exactly like the actual company's site.
Do not take these phishing emails lightly. They are never harmless. These emails represent illegal activities and are not just harmless pranks. The individuals behind these emails have spent a great deal of time in creating deceptive emails that look authentic. You need to be very cautious about all emails requesting personal information. Legitimate companies will not send you an email asking you to reveal personal information.
When examining your email, keep in mind that the "From Field" can be easily changed by the sender. While it may look like it is coming from a well know company, looks can be deceiving. Keep in mind that the phisher will spare no effort to make their email look as legitimate as possible. They will usually copy logos or images from the legitimate site. Finally, they usually include a clickable link that will take you to the deceptive website.
One way to check the legitimacy of the link is to point at the link with your mouse and observe the address in the bottom left hand screen of your computer. The actual website address to which you are being directed will be revealed here. It is a quick and easy way to check if you are being directed to a legitimate site. The address revealed is usually fairly long and complicated. For example, if they were masquerading as Amazon, rather than an address such as www.amazon.com/login, it could be something like www.amazon.mqrs.com/?login/142647/4598.php
Finally, never click the links within the text of the e-mail, and always delete the e-mail immediately. Once you have deleted the e-mail, empty the trash box in your e-mail accounts as well. If you are truly concerned that you are missing an important notice regarding one of your accounts, then type the full URL address of the website into your browser. At least then you can be confident that you are, in fact, being directed to the true and legitimate website.