I received an email with the subject "Your invoice from Apple #xxxxx".
It then continues by: "[...] your payment from "Pokemon Go was accepted [...]". That line made me sceptical. I just downloaded the app recently. How could the scammer know this? Was it just a good guess?
I assume it to be scam since:
- The sender is surpressed
- Typos
- No Username / data
- Generic text
- A suspicious little pdf
- Not the signature / style from your friendly, expensive fruit seller tech company
Some online warning sites already caught up on it
What I could think of:
- Another free app reports my other apps to the vendor
- A site I often visit has cookies that I was looking up stuff from
let's go pikachu
- My account could actually be compromized and someone has access to my records
- Many people have the app installed
If only a fraction of the people who have the app open the attached pdf the scammer wins.
Anyway, how could this be and what counter messurements can I apply?