I get mail like this from banks I don't have accounts with, credit cards that I don't have, Fedex, UPS, and a whole load of other supposed companies that I've never even heard of requiring my attention and to click on links or open zip files.
A huge number of people have Facebook accounts so lets say that they send that email out to 100,000 random email addresses. Maybe half of them will have Facebook accounts, a further 1% of those people will be dumbasses and open/click on the required attachment/link and of that 1%, half won't have adequate security and bam, that's access to 250 peoples computers or data.
|