Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).
Fun fact: still can in Chromium-based browsers.
https://textslashplain.com/2023/03/22/attack-techniques-spoo...