Statistic for the ages: Google email worm hit 1 million people in 1 hour.

#phishing gets the job done. Now imagine it wasn't a [tricky] but generic one and think about targeted phishing. This is why phishing/vishing and basic OSINT checks are first and reliable steps.

http://www.bbc.com/news/business-39798022

@sten0_SE there was yet another issue why this particular type of phishing technique was so effective: users are primed (especially Android users) to automatically grant any permission to any app regardless of whatever it might request. It's basically as automatic as clicking through an EULA.
@kwanre Now there's an evil phish - fake EULA page that redirects/installs. 😈