Phishing used to be a craft. Someone had to write a believable email, register a lookalike domain, and hope a few people clicked. These days, criminal groups sell that whole process as a subscription, and the tools do most of the thinking. That shift matters for any Australian small business where one person wears the hats of office manager, bookkeeper, and unofficial IT support.

In September 2026, Cloudflare and Microsoft took part in a coordinated effort with law enforcement partners to disrupt a phishing-as-a-service operation called "EvilTokens", according to Cloudflare's threat intelligence team, Cloudforce One. The platform itself first emerged on Telegram in January 2026, but the coordinated takedown came later in the year. Cloudflare said the platform was linked to more than 12,000 compromised inboxes across more than 10,000 organisations worldwide, and that Australia was among the countries with the highest concentration of victim activity.

The detail worth pausing on is what the service was built to do. Cloudflare said EvilTokens automated the collection of Microsoft Office 365 authentication tokens and was designed to hold onto access even after session tokens expired. In plain terms, changing your password might not have kicked the intruder out. Cloudflare also said the operation included an "AI coach" to help users write phishing lures, including guidance on US tax documents and common invoice and accounting formats. That is the pattern to watch: invoice and tax themes, aimed at whoever in your business handles the books.

You do not need to understand token theft to defend against it. You need a short list of habits and settings that hold up when an email slips through. Here is one, built for businesses with no dedicated IT staff.

Step 1: Turn on multi-factor authentication everywhere

Multi-factor authentication (MFA) is still worth having, even though services like EvilTokens are built to work around it. Cloudflare's account of the operation shows that MFA alone is not a complete answer, because the platform was designed to capture authentication tokens rather than simply guess passwords. Treat MFA as the floor, not the ceiling, and switch it on for email, accounting software, and any cloud service holding client records. Where you have the choice, app-based codes or a hardware key are stronger than SMS codes.

Step 2: Know which accounts would hurt most if they fell

Most small businesses run on a handful of logins: the email account, the accounting platform, the practice management system, the shared drive. Write them down. For each one, note who can access it and whether MFA is on. This is a one-page exercise, not a project. It also gives you something to hand a managed service provider if you later decide to outsource the technical side.

Step 3: Change how you handle payment and bank detail requests

Business email compromise usually ends with someone paying an invoice into the wrong account. Cloudflare's description of the AI coach points directly at invoice and accounting formats, which tells you where the pressure will land. Set a rule that any change to bank details is confirmed by phone, using a number you already have on file, never a number supplied in the email itself. Say this rule out loud to whoever approves payments.

Step 4: Give staff one simple way to report a suspicious email

Most people who click on a phishing email feel embarrassed and stay quiet, which is the worst outcome. Give everyone a single reporting address or button, and make clear that reporting a mistake is the right move. Speed matters more than blame. A report in the first ten minutes is a technical problem. A report three days later is a client notification problem.

Step 5: Run automated phishing testing for non-technical managers

This is where most small businesses stall, because traditional security awareness training means buying software, configuring campaigns, and interpreting results. Automated phishing testing for non-technical managers removes that barrier. You add employee names and email addresses through a dashboard, choose how often tests run, and the platform handles the rest: generating realistic simulated emails, tracking who opens or clicks, and assigning short training to anyone who needs it.

Platforms built for this purpose, such as cyber security training for small business, typically include a library of scenarios mimicking services your team already uses, from Microsoft 365 to DocuSign and LinkedIn. The value is not the gotcha. It is the teaching moment that follows, delivered while the lesson is still fresh.

If you are comparing options, look for best phishing test software Australia providers that report in plain language, adjust difficulty as people improve, and let you export records you can show an insurer or auditor. Reporting on AI-generated phishing campaigns often suggests the criminal side may be automating faster than many defenders, which is a reason to make your own testing routine rather than occasional.

Step 6: Cover the compliance basics without overthinking them

Under the Privacy Act and the Notifiable Data Breaches scheme, a serious data breach may need to be reported to affected individuals and to the Office of the Australian Information Commissioner. The Australian Cyber Security Centre publishes plain-English guidance for small business, and documented staff training is one of the easier things to show if you are ever asked what you had in place. Keep a simple record: who was trained, when, and on what.

If your obligations extend further, our guide to compliance reporting for online safety walks through what Australian small businesses currently need to track.

Step 7: Put a 30-minute review in the calendar each quarter

Check that MFA is still on for every account on your list. Check that new starters have been added to training. Check your test results and look for the pattern, such as one department clicking more than others. Then close the laptop. That is the whole review.

Where to start this week

Pick one step and do it today. If you want the fastest visible result, start with step five. Phishing Training Australia runs realistic simulations, tracks who falls for them, and delivers training automatically to the people who need it. Setup takes minutes: add your team, choose a frequency, and the system does the rest. Pricing typically starts with a free trial for a small number of users, with paid plans available for larger teams.

You can send yourself a test email before you commit to anything, which is a good way to see how convincing a modern simulation looks. Start your free trial and run one test on your own inbox. If it makes you pause, your team will pause too.