Microsoft has revealed a large-scale phishing scam that has targeted at least 10,000 organisations since September last year. The ongoing campaign, which can hack into user accounts even when they are protected by multi-factor authentication (MFA) measures, begins with a phishing email with an HTML attachment leading to the proxy server.