Social engineering is a massive attack vector for both enterprise and home users.
A friend received this crafty looking email this morning. Normally, I would just get them to check the link URL, then delete but this phish had used/guessed my name as the purchaser which was even more