Apparently things like this do happen, for example when people are buying or selling things on the internet. They get redirected to a pay processing site that looks just like the one from their bank, but steals their money and/or identity instead.
Apparently things like this do happen, for example when people are buying or selling things on the internet. They get redirected to a pay processing site that looks just like the one from their bank, but steals their money and/or identity instead.
A simpler attack would be to for the third-party attempt a login on their end into your account, and if you happen to click on the Magic Link generated by their login attempt, you wouldn't be signing yourself in, but them.
I click the magic link, expecting it to sign me in, but instead it takes me to a fake copy of the website which then asks (again) for login details?
This is fine, but ...
> ... which then asks (again) for login details?
This is where the trick lies. The third-party copy doesn't have to ask you for login details. As your parent states: They get redirected to a pay processing site that looks just like the one from their bank, but steals their money and/or identity instead.
The fake site doesn't have to show you details of your account. It has to look just similar enough that enough people will think it's a legit payment site and submit their payment details.
----
There's also a simpler, alternative attack I mention in a sibling comment: https://news.ycombinator.com/item?id=32081724
And this third party can find out how, exactly?
Or possibly just guessing without evidence because the sending cost of junk email is so low — looking at my junk mail folders, I have reason to believe they guess.
FWIW, I've heard of this type of attack (deliberately timed) being used during house purchases, with a fake destination bank message preceding the real message by a few minutes. Does anyone know if that's real or just an urban legend?