We are sending this to warn you of this new scam.

This morning, I received a cleverly composed and very official looking email from Experian telling me that a “Key Change” has been posted to my account.

Many of us have learned to not click links on emails, especially on ones that look fishy. Many also know to hover the mouse pointer over a link to reveal the web address, which usually points to some spurious site.

Well, this email (screenshot below) looked very official. The link looked legit. And the message is psychologically powerful – something important happened to your credit and you need to look into it right away. How? The instructions tells you to click on the attached file. What a clever way to distract and get your guard down.

Pretty sure the attached zip file contains some kind of malware.

By the way, I went to Experian’s website directly and downloaded a free credit report. Nothing unusual was in my account.

image001