The fake login page was never on the internet. Your browser built it.
Almost every piece of anti-phishing advice assumes there is a bad web page sitting on a server somewhere. Block the address, and the scam stops working. Research Barracuda published on 9 September quietly removes that assumption.
The email is Docusign-themed with a calendar invite attached. The invite does nothing at all; it is there so the message looks like ordinary business post. Click through and you land on Microsoft Teams, a genuine Microsoft service on a genuine Microsoft address, which then pulls content from an outside host called cdn.bloom[.]io. Your browser takes that content and turns it into a blob URL, a page assembled from data already in memory that exists only inside your copy of Chrome or Edge. The fake sign-in form is built on your own machine. There is no page for a scanner to fetch, no domain to add to a blocklist, and nothing left behind once you close the tab. Underneath, service workers and hidden frames report back so the operators can steer every victim from one place.
The technique is not brand new. Barracuda documented blob-based phishing in 2024 against people who banked with Capital One and Chase, and against Air Canada customers. What has changed is the routing through Teams, which makes the first several hops of the journey authentically Microsoft.
One tell survives all of it. When a sign-in page appears, read the address bar. A real Microsoft login lives at login.microsoftonline.com. A blob URL begins with blob: followed by a long string of nonsense. If you see that above anything asking for a password, close the tab. Better still, never sign in from a link: open a new tab and type the address yourself. Tendvane's Privacy and accounts check shows which accounts your PC is signed into and how each one is protected, which is the list you want in front of you the moment you suspect a password went somewhere it should not have.