The problem here really is that the user is already partially compromised and this is just the "capper". They may already have had their ID stolen but the greedy bastards need access to one last account...