how is this any worse than a spear phishing email that gives a login link to a malicious domain that looks the same as the official domain?