Somebody has created and deployed a tool which duplicates all of the important short IDs on the SKS keyservers. As a result, adding a key for many important projects - including in the way that their documentation instructions - now also adds "Totally Legit Signing Key <mallory@example.org>".
You can read more about this here:
https://seclists.org/oss-sec/2018/q3/174
The tool to perform the collisions is here:
https://github.com/jwilk/stopgp32
We got burned by this yesterday. Fortunately, the author is just trying to make a point and isn't doing anything malicious, but it would have been trivial for him or anybody else to cause serious damage.
Since it's trivial to spoof short IDs, I strongly recommend that this feature be disabled entirely and that only _full_ identifiers be used - even 64-bit identifiers are brute forceable for anybody with access to a well funded AWS account.