Random thought: the centralization of authentication to a few big OAuth providers like MS and Google, combined with services that time out your cookies and force relogins every so often, makes phishing people so much easier.
Want someone's account creds? Just pop up something that looks like a ms or google login form, odds are they're so conditioned by login fatigue that they'll automatically type their creds and TOTP token into it.