Hunt clicked on the link in the email.
There was also a login alert from the same IP.
These scams are automated so the processes take place before the victims can change their login credentials.

“Tiredness, was a major factor.
Hunt said he is now alerting affected users via email.
The domain used to host the fake website has been taken down by Cloudflare.