I read this article: http://it.slashdot.org/it/08/03/03/2049205.shtml
It just makes me shake my head. You should never click links out of email unless you trust the source, or you validate it. Anything that takes you to a paypal site without going through a shopping cart should be your first clue.
Plus if you get their security token, then your a lot more secure.