Exactly - also if you do any penetration testing of your staff side - the key to get something through is have the name of the company it seems anywhere in the URL. Literally - lkjljkdfskjfsd.com/bankofamerica/securelogin.do etc.
Part of the issue I've noticed is some sites actually do outsource things to other sites (microsoft has a lot of redirects on logins so you used to end up on passport.com I think to login, and then to something with azure, then office... etc). Combine this with subdomains and trailing urls and internationalization efforts and you are in trouble.
This must be just because of how we scan / read things? Ie, a quick cross check. A lot of people maybe don't parse all the elements properly (,.:?& etc).
The other issue - let's say just 2-5% of chrome users are confused. That still is a HUGE number that are confused.