It is unfortunately normal for companies to impersonate scammers.
We can teach people as much as we want about security against phishing. It won't matter because people have to break these rules constantly. Companies actively train people to fall for phishing by doing everything in their power to be indistinguishable from phishing themselves.
The worst are DHL, UPS, etc. customs payment mails. Even the real ones look like phishing mails and in some cases they don’t link the payment request to your account, so you cannot circumvent it by logging into your account and checking wether it is legit.