TLDR: They generated some phishing emails using LLMs, they sent the emails to 108 elderly people who agreed to be in a study, 11% of the recipients clicked a link.
Generating a phishing email isn't very difficult to do, with or without an LLM, and claiming that because someone clicked on a link, they were "compromised" seems disingenuous.
More interesting to me, is using LLMs in multi-turn phishing correspondence with victims, the paper mentions this in the discussion, but it isn't something that they appear to have actually tested.