Basically, they would recognize that sign a message is to prove the ownership (theirs) on that address (they must own private key to sign a message). It is weird when they do know the address they used does not belong to them. They can not know how the process goes but the address is not theirs (not sure how they can easily skip this important element).
In real life, how do I sign my signature on paper (contract, ie.) if the name is not mine?
Thanks OP for this interesting finding.