Using a real Office 365 account at a legitimate company to send out lures helps phishers evade email defenses.
Source: Threadpost