FYI: Latest phishing emails very convincing

#0 - July 31, 2010, 1:25 a.m.
Blizzard Post
I recieved a phishing email today saying that my main toon was undergoing a faction change. There were links to go to my account to view the transaction. Those links of course were to the scammer's server, but unless you look closely, they're very convincing.

Here's one - DO NOT GO THERE! (I changed the "zz" in blizzard to "xx" to prevent you from accidentally clicking.)

http://www.blixxard.com.verifyconfirm.net/faction-change-status.html

Here's how to tell where a link REALLY goes. Most email clients will show you the actual referenced link if you hover over the clickable link with the mouse pointer.

Look for the FIRST / (forward slash) after the http://, then look at what's immediately before it. In this example it's not blizzard.com, it's actually verifyconfirm.net which is the scammer's website. Everything before that is the "sub domain" of the website and a sub domain can be named anything, with any number of words with dots between them making it easy to spoof links like this.

Make it a habit to apply this simple technique to every link that gets emailed to you and you can save yourself a great deal of grief.
#4 - July 31, 2010, 1:36 a.m.
Blizzard Post
Excellent advice, Randomchance. More advice on how to tell a fake/phishing e-mail can be found in the following stickied thread.

Fake E-mails from "Blizzard Entertainment"
http://forums.worldofwarcraft.com/thread.html?topicId=965511383&sid=1