What’s the solution for preventing this kind of phishing attack?
TLS client certificates. Unfortunately, the browser UI for them ranges from godawful to removed-because-nobody-used-them.
TLS client certificates. Unfortunately, the browser UI for them ranges from godawful to removed-because-nobody-used-them.