“Shared a file with you” — then asks you to sign in again
Attackers send genuine OneDrive, SharePoint or Dropbox notifications from real, compromised supplier accounts. The trap is on the other side.
- Because the notification comes from the real service, it looks legitimate — and it is. The file is the problem.
- The file is often view-only and asks you to sign in again to see it. That sign-in page steals your password.
- Unexpected share, even from a supplier you know? Confirm with them by phone first.
- Open OneDrive or SharePoint directly rather than through the email link.
- Never enter your password on a page you reached from a shared document.
- Report the email so others in your business are warned.
Based on: Microsoft Security — File hosting services misused for identity phishing
Still stuck after those?
You’ve done the right thing by trying. Send whedo.it a quick note — what you tried, what you saw — and a senior pair of eyes will be on it the same business day.