ATO (Account Takeover) attacks have reportedly impacted roughly 4,000 Office 365 accounts, which were later used to carry out malicious activities. 1.5 million malicious and spam emails were sent from the hacked accounts in one month. The attacks begin with infiltration (with hackers impersonating Microsoft in 1 in 3 attacks) and the use of social engineering tactics to lure users into visiting phishing websites. Hackers would rarely launch an attack immediately after compromising an account. They would instead monitor the emails and track company activities, which would help maximize chances of executing successful attacks.”]
Source: https://hackercombat.com/ato-attacks-affect-around-4000-office-365-accounts/

