Medium riskEmail

Google Docs Sharing Scam

This scam sends an email saying someone shared a Google Doc or file with you, with an 'Open' link that leads to a fake Google login page or asks you to grant risky account permissions, aiming to capture your password or access your account.

Quick verdict

Risk level
Medium risk
Scam type
Document phishing scam
Main red flag
An unexpected 'document shared with you' email with an Open link that asks you to sign in again or approve account access.
What to do first
Do not click the link. Open Google Drive directly to check whether any file was really shared with you.

What to know first

This scam sends an email saying someone shared a Google Doc or file with you, with an 'Open' link that leads to a fake Google login page or asks you to grant risky account permissions, aiming to capture your password or access your account.

Email scams, or phishing, remain one of the most common ways criminals steal logins, payment details, and money. A convincing message imitates a brand or contact and steers you toward a fake login page, a malicious attachment, or a fraudulent payment.

The core pattern to watch for is clear: An unexpected 'document shared with you' email with an Open link that asks you to sign in again or approve account access. Do not click the link. Open Google Drive directly to check whether any file was really shared with you.

Related tricks worth knowing: the Fake DocuSign Email Scam and the Microsoft Account Email Scam. For the wider picture, browse the Email Scams guides or run the message through our scam checker.

Scam statistics

Most reported
phishing was the most common type of cybercrime complaint reported to the FBI in 2023
$12.5B
total reported internet-crime losses in the US in 2023

Tell-tale red flags

  • An unexpected file-share email from someone you do not normally work with
  • An Open link that does not lead to the genuine docs.google.com or drive.google.com address
  • Being asked to sign in again or approve permissions to view a simple document
  • A vague or generic file name with no context about why it was shared
  • Pressure to open the document quickly or before it 'expires'

Staying safe

  • Open Google Drive or Docs directly rather than using the link in the email
  • Hover over the link to check the real address before trusting it
  • If unsure, contact the sender through a separate, known channel to confirm
  • Report the email as phishing in your mail app and delete it

How it usually reads

Example pattern, not a real report
Example pattern: 'A document has been shared with you. [Sender] has invited you to view "Invoice_Q2_Final". Open Document: [suspicious link]. You may need to sign in to view this file.'

This is a fictional, anonymised example used to illustrate the pattern. It is not a verified real message, and any names are used only to show how the scam typically reads.

What to notice: An unexpected 'document shared with you' email with an Open link that asks you to sign in again or approve account access.

Steps if you already acted

  • Do not enter your password on the linked page; close it instead
  • If you signed in, change your Google password right away from the official site
  • Review and remove any unfamiliar apps with access in your Google security settings
  • Turn on two-step verification and check for forwarding rules or logins you do not recognise

Common mistakes

  • Do not enter your Google password on a page reached through the email link
  • Do not approve permission requests for apps you do not recognise
  • Do not assume it is safe just because the sender's name looks familiar

Scams like this one

Your questions answered

How can a Google Docs share be a scam?
Scammers copy the look of a real share notice but link to a fake login page or a permission request. The aim is to capture your password or gain access to your account.
It looks like it came from a contact. Could their account be hacked?
Yes. Compromised accounts are often used to send these emails, so a familiar sender name does not guarantee the message is safe. Confirm through another channel.
What is a risky permission request?
Instead of a password page, some versions ask you to grant an app access to your email or contacts. Approving it can let attackers read your account without your password.
How do I check if a file was really shared?
Open Google Drive directly and look under 'Shared with me'. If nothing matching the email appears there, treat the message as suspicious.

Last reviewed June 2026 · Written & reviewed by the

Disclaimer: This page provides educational information only to help you recognise common scam patterns. It is not legal, financial, cybersecurity, or law enforcement advice, and it does not confirm whether any specific message, company, or person is genuine or fraudulent. When in doubt, contact the official organisation directly and report concerns to your local authorities.