A phishing campaign that's gone undetected for at least six years is targeting customers of Microsoft's legacy single sign-on ...