“A document has been shared with you” is one of the least suspicious sentences in modern office work.
That is why it makes such a useful phishing lure.
Microsoft documented campaigns in 2024 that abused legitimate file-hosting services including OneDrive, SharePoint, and Dropbox. In some cases, the notification itself was genuine because the attacker had actually shared a file through the service. The malicious step came later, after the recipient opened the file and followed another link toward a phishing page.
See Microsoft’s analysis of file-hosting services misused for identity phishing.
A real notification can still lead into a fraudulent workflow
That distinction matters.
Users are often taught to inspect whether an email really came from Microsoft or Dropbox. That is useful, but a legitimate notification is not proof that the person who shared the file is legitimate or that every link inside the shared content is safe.
Microsoft observed restricted-access files that required the intended recipient to authenticate before viewing them. The file could then display a message or preview containing a second link. That later link sent the user toward an adversary-controlled sign-in flow designed to capture credentials and authentication data.
The attack therefore borrows trust in several layers:
The familiar cloud service. The ordinary “shared with you” workflow. The expectation that a private document may require sign-in. And often an urgent business pretext telling the recipient to review something quickly.
Check the task from inside the service
If a document-share notice is unexpected, do not let the email define the entire path.
Open the cloud service through a known bookmark, company portal, or official application and check whether the file appears there. Verify who shared it. If the document itself immediately sends you somewhere else to authenticate again, slow down and inspect the destination.
A legitimate shared file may require authentication to the hosting service.
It should not make an unrelated domain become trustworthy simply because the journey started in OneDrive or Dropbox.
The useful mental model is that a shared document is content, not authority.
Someone can place a dangerous instruction inside a perfectly real file-sharing system.
The email can be genuine.
The file can be genuine.
The trap can still be the next click.
