Wouldn't it be clever if a phisher first sent an email, warning you that the next time you log on to a service, say Dropbox, you would be asked to change your password. Then, you log on to what you think is that service, but it's a scam, and your defences are down …