Nobody wins every single time against the most sophisticated attackers in the world. Microsoft put up a very respectable fight here. When a random small-to-medium enterprise IT department gets owned, it’s for some braindead stupid low-hanging-fruit reason. Attacks like this don’t happen because they are unnecessary.
There was no respectable fight. They used the same signing key for all customers AND own corporate mail. It's a stupid rookie mistake. Exactly the type you would expect from a small-to-medium IT department.