This is an ongoing issue for us, too. Fortunately, most of our clients have recognized that something is not quite right and reached out to us about it, but at least one client (that we know of) was tricked into temporarily giving staff account access to the scammer.
As they are creating staff accounts, not partner accounts, some sort of warning when a merchant tries to add a staff email that is similar to a collaborator email/collaborator account name might be a mitigating measure.