Microsoft discovered numerous phishing campaigns in which malicious actors attempted to spoof its new Azure AD sign-in page. Microsoft Security Intelligence said the spoofing attempts first appeared in its Office 365 Advanced Threat Protection (ATP) data on May 14. Attackers sent out attack emails with the subject line, Business Document Received. The messages attempted to trick recipients into clicking on what appeared to be a OneDrive document. In reality, the attachment was a PDF document that redirected recipients to a phishing site.”]

