A couple of stories here from the BBC indicating that people are still falling for phishing schemes.
It obviously bears repeating; NEVER give out your username and/or password to anyone. Ever. Not by phone, email, snail mail or in person.
Legitimate companies will never solicit you for your personal information, so assume that if you are ever contacted and any personal information is requested that it is a scam.