The arms race between scammers and defenders continues.
It does seem like sooner or later, if someone is able to build a reliable AI model of my face and voice, they could even phish my own relatives by video call.
Seems like a Philip K. Dick novel—objective reality is something you could only see around you, while the machine would be completely untrustworthy.
The emails Inky detected instruct the employee to resolve security issues such as a missing two-factor authentication enrollment or to change a password and warn of repercussions that may occur if the recipient fails to follow through. Those who take the bait and click on the QR code are led to a site masquerading as a legitimate one used by the company but it captures passwords and sends them to the attackers.
An attack that would be protected against with a yubikey, webauthn, or passkey.