At the end of the day it's a phishing attack that was successful in the case of those who's details were revealed.
It's not the EMail clients fault. It's the lack of security at the consumer end that is the problem. How many fake emails do you see in your mail box, either as junk or whatever and how many do you actually respond to by clicking a link in the email. None, I'll bet.
EMails with a link do not get flagged as a virus. They only get flagged as possible junk or a possible security risk. If you don't have any security measures in place they might not get flagged at all.
It's was the end user clicking a link, and then confirming their password that led to this whole issue in the first place.
|