The various companies we interact with online need to up their game as well as they constantly send mixed messages which then leads to complacency and/or confusion within the average consumer base.
A prime example are the various banks. If I access my bank acounts online I require multi-factor authentication with smartcard readers or pin code type tokens from one of the various vendors. If I phone them up on one of their published numbers they require me to answer security questions to authenticate myself.
All well and good so far.
The banks also make a point of printing on my statements that they will never ask me for account details etc in email or over the phone - and then completely break that rule every single time they phone me! The conversation goes something like
them: "Hi this is XXX calling from YYY. Could I just take you through security to verify your identity ?"
me: "No because you called me so I have no idea if you are who you say you are"
They usually get quite irate at that point for reasons that are beyond me. However the point is if our banks insist on phoning us up and asking us to give them security check information is it any wonder your average consumer then falls prey to various phishing scams since they have been conditioned that whilst their bank says they do not do it they do it every time they call them!