Yesterday I emailed my office reminding them to be extra vigilant about phishing emails. It's the holidays, we're busier, we're shopping more, and packages are being shipped all over. Basically, we're more susceptible to this kind of crap.
A couple of hours later one of the staff says they got an email with an attachment, they clicked it and got an Office 365 login screen.
They entered their credentials.
** head desk **