tomspark wrote:
11 steps is wild for a phishing attack, but honestly this is why people need to stop trusting email links entirely. Use a password manager with autofill (only fills on exact domain match) and you're already way ahead of 99% of users getting compromised by this stuff.