This email, which purports to be from online payment processor Stripe, claims that you have received a payment of $880.
The email, which includes information about the supposed transaction, features a button labelled “View in Stripe Dashboard:
However, the email is not from Stripe and it does not contain information about a real payment. Instead, it is a phishing scam designed to steal your Stripe and email account login details.
If you click the Dashboard button, you will be taken to a fraudulent website that asks you to enter your Stripe email, password, and phone number:
At first glance, signing in on the fake site appears to open your Stripe profile page. However, the profile is fake and a popup “account Information” window will ask for your email and email password as well as your linked account number:
After you enter the requested information, you will be automatically redirected to the genuine Stripe website.
Meanwhile, online criminals can collect the information you supplied and use it to hijack your Stripe account and conduct fraudulent transactions in your name.
They can also use the stolen information to access your email account. Once in, they can use your email account to send spam, scam, and malware emails that will appear to come from you. They may also be able to access linked services such as app stores or online storage, conduct further fraudulent transactions, and steal your documents and personal information.
Stripe includes information about identifying and reporting phishing scams on its website.