If you run a small business in Gippsland or regional Victoria, chances are you sign contracts, invoices and supplier agreements electronically almost every week. That convenience is exactly what a new wave of cybercriminals is exploiting. Security researchers have uncovered a subscription-based phishing toolkit called NovaCookies that hides inside genuine-looking Docusign notification emails to steal Microsoft 365 login sessions – and it’s clever enough to slip past multi-factor authentication (MFA) in many cases.
This isn’t a clumsy scam email full of spelling mistakes. It’s a polished, professional operation being sold as a service to other criminals for around $320 a month. That means it’s cheap enough and easy enough that it will almost certainly show up in regional Australian inboxes, including yours.
Docusign is one of the most trusted names in business – almost everyone recognises the “you have a document to sign” email format. NovaCookies takes advantage of that trust by sending emails that look exactly like real Docusign notifications. When a staff member clicks through to “view the document,” they’re actually taken to a fake login page that sits invisibly between them and Microsoft’s real login system.
This technique is called an adversary-in-the-middle (AitM) attack. Instead of just stealing a password, the attacker’s server quietly relays the login attempt to the real Microsoft 365 system in the background. When the employee enters their username, password, and even their MFA code, the attacker captures the resulting authenticated session – essentially a digital “cookie” that proves the user is logged in.
That stolen session can then be used by the criminal to log straight into the business’s Microsoft 365 account, no password or MFA code required a second time, because the session already looks fully verified. It’s a bit like handing someone your building access card after you’ve already used it to unlock the door – they don’t need their own key, they can just walk in behind you.
For years, small businesses have been told (correctly) that turning on multi-factor authentication is one of the single best things you can do to protect your accounts. That advice still holds – MFA stops the vast majority of basic password-guessing and credential-stuffing attacks. But AitM toolkits like NovaCookies are specifically designed to get around standard MFA by intercepting the session after authentication happens, rather than trying to guess the password beforehand.
This matters because a lot of business owners assume that once MFA is switched on, the job is done. In reality, MFA needs to be paired with other layers of protection and, just as importantly, with staff who know what a suspicious login prompt looks like.
Small and medium businesses across regional Victoria are attractive targets precisely because they often run on Microsoft 365 with fewer dedicated IT security staff than a metro enterprise. A compromised Microsoft 365 account gives an attacker access to:
For a trades business, professional services firm, or retailer relying on email for quotes and payments, this kind of compromise can be financially devastating and deeply damaging to client trust – particularly in tight-knit regional communities where reputation travels fast.
As reported by The Hacker News, the NovaCookies campaigns are built specifically to mimic genuine Docusign notifications closely enough to fool a busy employee glancing at their inbox. Still, there are some habits that help:
You don’t need an enterprise security team to meaningfully reduce this risk. A few practical, achievable steps make a real difference:
Phishing has moved well beyond obvious scam emails. Toolkits like NovaCookies show that criminals are investing real time and money into making attacks look indistinguishable from everyday business tools you already trust – Docusign, Microsoft, DocuSign notifications, calendar invites, and more. For a small business, the best defence isn’t a single tool or setting; it’s a combination of sensible technical controls and a workplace culture where staff feel comfortable pausing to double-check something that seems slightly off, even when it looks completely legitimate.
Cybercriminals are increasingly targeting the trust businesses place in everyday software, not just weak passwords. Taking a few practical steps now – stronger MFA, conditional access, and staff awareness – can be the difference between a normal Tuesday and a very costly one.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804