I'm not sure what kind of websites are vulnerable to these attacks, but websites that have double authentication seem pretty safe to me. And if you forgot your password, then you receive an e-mail to change it with a secure link.
This point means the user is not paying attention: 1) User goes to BAD website and signs up.
Steps 2-7 wouldn't be possible without 1.