There are many phishing scams. Smart and well designed, but also those that are very casual and prominent. Phishing scams use various methods and aim to spy on their victims' logins to some "interesting" service.
A new scam that appeared and is currently running (according to Lifehacker) comes from Gmail's inbox.
The message seems to include an attachment, which in fact is not what it claims to be. We report this fraud only because it is currently being circulated, not because it is well designed.
The following figure shows how this fraud looks like:

If you click, as you do when you see an attachment, you will be taken to a Google page where you will be asked to enter your password.
Of course, the page that will open is false. It is actually a data URI with the prefix "data: text / html", and does not use the usual HTTPS connection you would expect.
https://twitter.com/tomscott/status/812265182646927361
Note that Chrome v56.0.2924 tries to address issues like this by displaying a "Not Secure" message in the address bar.
In addition to controlling the URL that is essential if you want to protect yourself from such scams, the next time you want to click on a Gmail attachment, you should think it very well.
Generally, you should be very skeptical when you come across attachments from people you do not know, but also from people you know why their accounts may have been violated. Besides, you are on the internet, where everyone can claim to be whoever wants.
George is still wondering what he is doing here….

