
> victim of a 'spear phishing' attack... diverted to a spoofed Office 365 login page where he entered his credentials, unwittingly passing his email address and password to unidentified cyber criminals."
If he was the victim of a phishing attack then they already had his email address.