The big advantage of an OpenPGP signature over a checksum/hash is that you only have to verify the identity once. The identity can be used to verify the signatures of an unlimited number of files. That is as opposed to requiring each file to have a separate checksum/hash. Much more opportunity for deception on the smaller scale.
A perhaps less appreciated advantage is that in practice the identities are stored offline with each entity that will be verifying the signatures. So an attacker has to justify the use of the new identity to what would normally be a large number of entities. That might explain why that sort of attack is so rare.