Statistic for the ages: Google email worm hit 1 million people in 1 hour.
#phishing gets the job done. Now imagine it wasn't a [tricky] but generic one and think about targeted phishing. This is why phishing/vishing and basic OSINT checks are first and reliable steps.