# Researchers detail NovaCookies Microsoft 365 session-theft service

_Wednesday, August 26, 2026 at 9:44 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers detail NovaCookies Microsoft 365 session-theft service — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz4GD3giiT1DIPT5Q13XvCZcwC8-STaGCZ3KbqUzQ5Q9oniGfA0Odbqfmwva6B-xSSTD2QG1wdqu5fFOleaBVFSA-t3ZfeqpcrYOEomdygWsZOONJXYcpxhRdT-EbTS_DZ0zYLrH_-1YN7TjXCsDuIj0I2G53mFT0df1HC3tjUdUQ5MCdHdEo27rDE2QEm/s1700-e365/docusign.jpg)

Researchers disclosed NovaCookies, a subscription phishing platform that proxies Microsoft 365 sign-ins and captures authenticated sessions after victims submit passwords and multifactor-authentication codes. Island said the $320-per-month service has targeted hundreds of organizations in the United States, United Kingdom, Canada, Germany, Israel and the United Arab Emirates. Observed campaigns used genuine DocuSign notifications carrying counterfeit document-share lures, sometimes passing through legitimate Microsoft or Google sign-in endpoints before reaching attacker-controlled infrastructure. Proofpoint assessed NovaCookies as a Sneaky2FA variant.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html)

---
Canonical: https://techandbusiness.org/newswire/OKr2hfm5fl6EqkbjKYb5FW
Retrieved: 2026-08-26T19:39:15.116Z
Publisher: Tech & Business (techandbusiness.org)
