The fact this kind of information came via email is the real give away. It is very simple no bank, web email, ebay, pay pal etc etc will very send you any request asking you to varify your user and password.

On a side note an attacker does not even have to use javascript to achive the attack. By exploiting a flaw where the attack an inject code into the site, they can use simple HTML code to create a new form on the page, but that form porsts the data to their web site and not the banks. Thus no popup etc. But that is just one way this attack can be done.

SittingDuck