There's a terrible enterprise security product that can be configured by IT to quasi-MITM your company web traffic. Instead of relying on enterprises pushing their own trusted root certs and MITMing the whole session this terrible product redirects all traffic to (and I'm not kidding here) urls like "www.terriblesecuritycompanyname.com/www.originalurl.com" when the user accesses www.originalurl.com.
So this "enterprise security" company encourages end users to put information such as passwords into www.terriblesecuritycompanyname.com/owa.office365.com for example. Of course everyone has SSO enabled for Office 365 but everyone is also used to SSO sometimes breaking and falling back to forms based auth so people have no issue typing their passwords into any page that looks somewhat legit as long as the URL is close to what they expect and has a little lock next to it.
Anyway www.turriblesecuritycompanyname.com is available and I'm waiting for someone nefarious to purchase it and start sending phishing emails with links to www.turriblesecuritycompany.com/owa.office365.com embedded in them.