“Normally, these kinds of emails are supposed to get caught by spam filters, but because they’re being sent via an official Microsoft address, they’ve managed to get through the eye of the needle. It’s not entirely clear how these hackers managed to send the extortion emails as of this writing, but according to BleepingComputer, the incident is currently being investigated by Microsoft.”
So… again, after the fact, Microsoft investigates. Does MS do ANY testing?
https://www.pcworld.com/article/2524078/hackers-are-exploiting-microsoft-365-to-send-extortion-emails.html