What to look out for today
1) “Real-looking DocuSign” emails used to steal Microsoft 365 sessions. Researchers report campaigns abusing genuine DocuSign notifications to trick people into signing into Microsoft 365 via a proxy page that captures an authenticated session (so criminals can access mail/files even if the password is later changed).
2) Business disruption ripple effects from large cyber incidents. Boston Scientific reports a cyberattack disrupting operations globally. Even if you’re not in healthcare, events like this often trigger knock-on issues: delayed deliveries, supplier/customer service disruption, and scam emails pretending to be “the affected company”.
3) SaaS authentication changes that can break data flows. Snowflake is ending password authentication for legacy service accounts, pushing passwordless methods. The hard part is identifying what apps/jobs still use those accounts and who owns them.
Why this matters to smaller businesses
- Session theft is not “just a bad password”. If an attacker captures a Microsoft 365 session, they may access email, SharePoint/OneDrive, and internal messages without repeatedly logging in.
- DocuSign and Microsoft 365 are common in SMEs. High-volume, familiar brands lower suspicion—especially in finance, HR, and admin teams.
- Supplier incidents create opportunity for scams. Attackers commonly exploit newsworthy disruption to send fake “updated bank details”, “rescheduled delivery”, or “urgent invoice” messages.
- Service accounts are a hidden dependency. A change in authentication (or a rushed fix) can break reporting, integrations, data pipelines, and customer-facing services.
Warning signs
- DocuSign-style emails that prompt you to sign in to view a document, especially if unexpected.
- Any sign-in page that looks “normal” but arrives via an email link and feels slightly unusual (extra step, odd domain, repeated prompts, or unexpected MFA flow).
- Messages referencing a major incident and asking you to change payment details, reroute deliveries, or open “urgent” attachments.
- Sudden failures in dashboards, scheduled reports, data exports, or overnight jobs (a clue a service account/integration is brittle or mis-owned).
How attackers may exploit the situation
- Adversary-in-the-middle phishing: the victim is relayed to a convincing Microsoft 365 sign-in experience while the attacker captures the session token and reuses it.
- Business email compromise follow-on: once in M365, attackers may read invoice threads, create forwarding rules, or send “payment change” emails from a real mailbox.
- Incident-themed impersonation: criminals may pretend to be a disrupted supplier (or their logistics/collections team) to pressure staff into fast decisions.
- Integration outages as cover: when services are unstable, fraud attempts can look like “normal disruption” and slip past process.
What to do today
- Tell staff (especially finance/admin/HR): do not sign in to Microsoft 365 from a document email link. Go to Microsoft 365 directly via bookmark/app, then open the document from there if it’s real.
- Reinforce payment-change controls: any bank detail change must be verified using a known, saved phone number (not the email signature).
- Quick check in Microsoft 365: review recent sign-ins and watch for unfamiliar locations/devices; ensure MFA is enabled for all users.
- Inventory service accounts: list what integrations/ETL/reporting jobs exist, who owns them, what data they access, and whether they still need that access.
Ask your IT provider
- Can you confirm our Microsoft 365 sign-in protections are set up to reduce session-token phishing risk (e.g., strong MFA enforcement and conditional access where available)?
- How quickly can you detect and respond to suspicious mailbox behaviour (forwarding rules, unusual OAuth/app consents, mass downloads)?
- Do we have a tested process for supplier compromise/payment diversion incidents (who approves, who verifies, how we document the callback)?
- Do we have a service account register (owner, purpose, permissions, last used), and a plan for any SaaS authentication changes that could break automations?
Patch watch - only one short paragraph, and only if relevant
Some attackers are reported to be targeting a Microsoft SharePoint remote-code execution chain. If you run on-prem SharePoint servers (not just SharePoint Online), treat this as an urgent “are we exposed?” check with your IT provider and ensure internet-facing servers are reviewed and updated promptly.
One action today
Send a same-day staff note: “Don’t sign in to Microsoft 365 from DocuSign/document email links—go to M365 directly; and verify any payment detail change by a known callback number.”
Related Actions On Cyber resource
Actions On Cyber checklist: Supplier payment change (invoice diversion) verification process
Sources
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions (The Hacker News)
- Boston Scientific says cyberattack disrupted operations globally (BleepingComputer)
- Snowflake ends service-account passwords. Now comes the hard part (BleepingComputer)
- Hackers target Microsoft SharePoint RCE chain with PoC exploit (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.