To be fair, every platform which allows user-generated HTML pages suffers massively from phishing and most of them don't deal with it very well: Google, Microsoft, smaller players like Codebox and countless others. Then there's phishing on Dropbox, phishing on Google Forms, OneDrive, etc. Then you have phishing at all the various hosters like DigitalOcean, CloudFlare, etc. Even there you'll sometimes have IPs which have hosting phishing pages for various brands for a long time. It's not an isolated problem. Some deal with it more aggressively, true, but the pace and ease with which phishing can be stood up and modified makes it a whac-a-mole. Plus, the expectation is that most phishing pages will only be active for a few hours before being taken down and/or detected, so phishers pump out new ones on a constant basis.
I run the service at https://urlscan.io which tracks phishing and frequently run into these cases which render any kind of black/whitelisting impossible. Imagine Microsoft phishing hosted on Microsoft domains and infrastructure. Here's a fun search which will return lots of phishing on windows[.]net and googleapis[.]com: https://urlscan.io/search/#page.domain%3A(googleapis.com%20O...