
They got a link that just said, "Hey, your your login's about to expire." And it said login-elastic.co instead of log instead of log elastic.co. It looked almost the same. They click on it, it come brings up our corporate website. They log in, everything looks cool, and then they get logged in and it says, "Thanks for refreshing your token." And then they close and go about their day. Meanwhile, the attackers have it. Now, they have an identity token.