The recent Heartbleed attack on eBay may have sparked some flow-on effect.
This morning, I received a genuine-looking confirmation email from PayPal, about payment for a purchase I (allegedly) made recently. It contained the usual link to the item I bought - except I know I didn't buy it.
In case anyone receives a similar "dodgy" message, please be careful and don't click on any link:
The email differed in at least three key features that gave it away as being fake:
The salutation just said "Hello:" whereas PayPal will greet their clients with the full name;
The paypal address, from which it was sent, has some extra characters in it;
Although it was sent to my correct email account, PayPal uses my client name as Alias; the fake didn't.
I forwarded the fake to spoof at ebay.com.au and hope it helps them catch the barstuds.