Logo

Fake Docusign Alerts Are Stealing Microsoft 365 Logins

If you run a small business in Gippsland or regional Victoria, chances are you sign contracts, invoices and supplier agreements electronically almost every week. That convenience is exactly what a new wave of cybercriminals is exploiting. Security researchers have uncovered a subscription-based phishing toolkit called NovaCookies that hides inside genuine-looking Docusign notification emails to steal Microsoft 365 login sessions – and it’s clever enough to slip past multi-factor authentication (MFA) in many cases.

This isn’t a clumsy scam email full of spelling mistakes. It’s a polished, professional operation being sold as a service to other criminals for around $320 a month. That means it’s cheap enough and easy enough that it will almost certainly show up in regional Australian inboxes, including yours.

What’s actually happening

Docusign is one of the most trusted names in business – almost everyone recognises the “you have a document to sign” email format. NovaCookies takes advantage of that trust by sending emails that look exactly like real Docusign notifications. When a staff member clicks through to “view the document,” they’re actually taken to a fake login page that sits invisibly between them and Microsoft’s real login system.

This technique is called an adversary-in-the-middle (AitM) attack. Instead of just stealing a password, the attacker’s server quietly relays the login attempt to the real Microsoft 365 system in the background. When the employee enters their username, password, and even their MFA code, the attacker captures the resulting authenticated session – essentially a digital “cookie” that proves the user is logged in.

That stolen session can then be used by the criminal to log straight into the business’s Microsoft 365 account, no password or MFA code required a second time, because the session already looks fully verified. It’s a bit like handing someone your building access card after you’ve already used it to unlock the door – they don’t need their own key, they can just walk in behind you.

Why MFA alone won’t save you here

For years, small businesses have been told (correctly) that turning on multi-factor authentication is one of the single best things you can do to protect your accounts. That advice still holds – MFA stops the vast majority of basic password-guessing and credential-stuffing attacks. But AitM toolkits like NovaCookies are specifically designed to get around standard MFA by intercepting the session after authentication happens, rather than trying to guess the password beforehand.

This matters because a lot of business owners assume that once MFA is switched on, the job is done. In reality, MFA needs to be paired with other layers of protection and, just as importantly, with staff who know what a suspicious login prompt looks like.

Why this matters for regional small businesses specifically

Small and medium businesses across regional Victoria are attractive targets precisely because they often run on Microsoft 365 with fewer dedicated IT security staff than a metro enterprise. A compromised Microsoft 365 account gives an attacker access to:

  • Email history, including invoices, quotes, and client correspondence
  • The ability to send convincing follow-up phishing emails to your clients and suppliers, “from you”
  • Access to shared files in OneDrive or SharePoint
  • A launchpad to redirect invoice payments to fraudulent bank accounts

For a trades business, professional services firm, or retailer relying on email for quotes and payments, this kind of compromise can be financially devastating and deeply damaging to client trust – particularly in tight-knit regional communities where reputation travels fast.

How to spot the warning signs

As reported by The Hacker News, the NovaCookies campaigns are built specifically to mimic genuine Docusign notifications closely enough to fool a busy employee glancing at their inbox. Still, there are some habits that help:

  • Hover over links before clicking (on desktop) to check where they actually lead – if the domain isn’t docusign.com or your organisation’s known domain, stop
  • Be suspicious of any “document to sign” email you weren’t expecting, even if it looks legitimate
  • Watch for login pages that ask for your Microsoft password when you weren’t trying to log into Microsoft
  • If a page asks you to re-enter your MFA code unexpectedly, treat that as a red flag rather than routine

Practical steps your business can take now

You don’t need an enterprise security team to meaningfully reduce this risk. A few practical, achievable steps make a real difference:

  • Use phishing-resistant MFA where possible – security keys (like FIDO2/passkeys) are far harder for AitM toolkits to intercept than SMS codes or app-based one-time codes.
  • Turn on conditional access policies in Microsoft 365, such as blocking sign-ins from unfamiliar countries or requiring device compliance – your IT provider can set these up.
  • Enable alerts for suspicious sign-ins so unusual login locations or times trigger a notification to your admin.
  • Train staff regularly on how to check links and sender details before clicking, especially for anything related to signing documents or invoices.
  • Verify unexpected document requests by phone or a separate message rather than clicking through, particularly for anything involving payments or contracts.
  • Review your Microsoft 365 sign-in logs periodically – or have your IT provider do this for you – to catch anomalies early.

The bigger picture

Phishing has moved well beyond obvious scam emails. Toolkits like NovaCookies show that criminals are investing real time and money into making attacks look indistinguishable from everyday business tools you already trust – Docusign, Microsoft, DocuSign notifications, calendar invites, and more. For a small business, the best defence isn’t a single tool or setting; it’s a combination of sensible technical controls and a workplace culture where staff feel comfortable pausing to double-check something that seems slightly off, even when it looks completely legitimate.

Cybercriminals are increasingly targeting the trust businesses place in everyday software, not just weak passwords. Taking a few practical steps now – stronger MFA, conditional access, and staff awareness – can be the difference between a normal Tuesday and a very costly one.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions