In part, that's because all the people who got nerd-sniped by this didn't ever actually send a response back. In part, it's because several different business units decided to try to Handle It without doing the rational thing of centralizing to legal counsel.
I think it is more nuanced than that -- they are sending a message via LinkedIn, is it really the company or a scam?
You should take time to respond appropriately and not be rushed in all cases. By acknowledging the message they'll want to continue the discussion. It's probably worth considering a standard response to approaches like this, along the lines of "Please contact us on generic-something@domain, I cannot discuss this on my personal social media account."
Since their behavior is indistinguishable from scammers, it probably makes sense to also ask procurement/design to additionally ban the vendor.
Piece of advice for the future: if you receive a message like this, and don’t want the sender to reach out to other people in your organization — acknowledge the message.