Washington Post SecurityFix blog has an interesting article about a new and rather sophisticated phishing scheme. The email not only used the first few digits of the users card number to look more plausible (even though the first part of the number is the same for all cards), but it also used a valid SSL certificate for its domain name.
Remember no financial institution would ask for your SSN, address or credit card number by email, or ask to to go to a web page that would ask for the same. They have this information. This includes Banks, eBay, PayPal or Amazon.com. Notice, they are using known numbers of your credit card, not the unknown numbers.