Phishing campaigns do not always rely on spoofed domains, compromised accounts, or obvious impersonation. Rather than building trust, some attackers are borrowing it — blending seamlessly into expected enterprise workflows by abusing legitimate SaaS infrastructure. In a 2026 campaign using Microsoft Dynamics 365 Marketing redirect functionality, one group of attackers delivered phishing payloads by leveraging the reputation of a Microsoft‑owned domain.