As far as phishing goes, few things are more effective than popping a medium sized law firm and sending form letters from their (legit) systems as a real person.
Click-through rate for a technically legitimate "you are party to a lawsuit" email must be sky high.