I think the idea is ambiguity between a zip file from your coworkers website and an entirely separate phishing website which downloads an entirely different zip file with a malicious payload.
Anything that introduces unnecessary and previously unforseen ambiguity to the olds is just another path to filling the internet with scams
Anything that introduces unnecessary and previously unforseen ambiguity to the olds is just another path to filling the internet with scams