Off-the-shelf phishing kits have quietly become one of the biggest force-multipliers in cybercrime. Instead of building a convincing fake Microsoft 365 login page from scratch, an attacker with no technical skill can now buy or rent a ready-made kit that handles the fake page, the credential capture, and often the multi-factor bypass too.
That's the pattern behind the recent wave of law-enforcement warnings about kits targeting Microsoft 365 specifically: it's the platform most businesses live in every day, which makes a convincing fake login page one of the highest-value targets an attacker can build.
The practical defence hasn't changed, even as the tooling gets slicker: verify the sender and the link before entering credentials anywhere, use phishing-resistant MFA where you can, and make sure your team knows reporting a suspicious login prompt is always the right call: never something to feel embarrassed about.
See how goDeep turns thinking like this into training your team will actually remember.