but how can they stole your data? I mean to get a virus logger you need to download and run an .exe right? And to get phishing you need to fill in your secret key that I think not many are that naive to share it.
what else can go wrong?
Because people are going to cloned websites of myetherwallet and filling in there private keys thinking they are logging in to there wallets. Than the attackers have there private key and just simply transfer all there funds out. This is a prime example of a phising website right here. DO NOT CLICK ON THE LINK UNLESS YOU ARE USING A VM OR SOMETHING ELSE SECURE :
https://www.enigma.co/token-distribution-d5fb6ce450af - see how the name of myetherwallet is slightly different. Phishers just send out mass scams like that and get a ridiculous amount of people with them.