But here, the attacker was clearly able to actually use 2K’s systems to contact customers from the official account, and as such bypass any of the usual spam filters or common-sense bullshit detectors a person may have in place.
The statement says, “We will issue a notice when you can resume interacting with official 2K help desk emails,” which is...not a foolproof method.
For those that think they may have already fallen for the phishing scam, 2K recommends that people reset all passwords, enable multi-factor authentication (but avoid text message-based verification!), clog up their PCs with anti-virus software, and “check your account settings to see if any forwarding rules have been added or changed on your personal email accounts.”.