It has a history of this usage, eg https://blogs.akamai.com/2020/01/protecting-websites-from-ma...
It relates the attack to something a lay person can easily absorb. As their security blog is written for a lay person (ie, IT manager type person who has some understanding of infosec but probably not their day job), who will not care too much about the nuances of how the attack is perpetrated, the term serves them well.