I received this PM yesterday:
It has what looks like a BCT link, but when you hover over it you see that it really opens in a different domain (as seen on bottom left). I checked it on my smartphone, and it turns out to be a page that looks identical to the BCT login page, with your name already in the field.. all you need to do is write in your password and click 'login'.
You have been warned.