It turns out that halfway clever phishing attacks really, really work

Some of us access g-mail through non-web clients (Apple Mail in my case).
Still, if i got one of these, i’d open up another window and open g-mail there to see whether i got automatically signed in as expected, showing the scam to be what it is.