Medium riskEmail

SharePoint Phishing Scam

This scam sends a fake Microsoft SharePoint or OneDrive email saying a document has been shared with you, linking to a counterfeit Microsoft login page designed to steal your work email credentials. It is commonly aimed at businesses.

Quick verdict

Risk level
Medium risk
Scam type
File-sharing phishing scam
Main red flag
A 'document shared with you' email pushing you to sign in through a link to view it.
What to do first
Do not sign in through the email link. Open SharePoint or OneDrive directly from your usual bookmark or app instead.

How this scam works

This scam sends a fake Microsoft SharePoint or OneDrive email saying a document has been shared with you, linking to a counterfeit Microsoft login page designed to steal your work email credentials. It is commonly aimed at businesses.

Email scams, or phishing, remain one of the most common ways criminals steal logins, payment details, and money. A convincing message imitates a brand or contact and steers you toward a fake login page, a malicious attachment, or a fraudulent payment.

In short, the giveaway is usually simple: A 'document shared with you' email pushing you to sign in through a link to view it. Do not sign in through the email link. Open SharePoint or OneDrive directly from your usual bookmark or app instead.

Scammers rotate tactics constantly, the same operation may also run the Microsoft Account Email Scam and the Google Docs Sharing Scam. See the full Email Scams guides hub, or test a suspicious message with the scam checker.

How to spot this scam

  • An unexpected file-share notice from someone you do not usually exchange documents with
  • A sign-in prompt that appears after clicking, asking for your work email and password
  • A link or login page address that is not a genuine Microsoft domain
  • Pressure that access will 'expire' or be removed unless you act quickly
  • Small wording or branding inconsistencies in the email or login page

What the message looks like

Example pattern, not a real report
Example pattern: 'A document "Q3 Invoice.xlsx" has been shared with you on SharePoint. Sign in to view the file before access expires: [suspicious link]'

This is a fictional, anonymised example used to illustrate the pattern. It is not a verified real message, and any names are used only to show how the scam typically reads.

What gives it away: A 'document shared with you' email pushing you to sign in through a link to view it.

The scale of it

Most reported
phishing was the most common type of cybercrime complaint reported to the FBI in 2023
$12.5B
total reported internet-crime losses in the US in 2023

How to protect yourself

  • Do not click the link or enter your credentials
  • Open SharePoint or OneDrive directly through your usual app or bookmark to check for any shared file
  • Verify with the supposed sender through a separate, known channel
  • Report the email to your IT or security team and delete it

Already responded? Do this now

  • Do not enter any more information on the page
  • Change your work email password immediately from a trusted device
  • Turn on or confirm multi-factor authentication on the account
  • Report it to your IT or security team so they can check for unauthorised access

Mistakes to avoid

  • Do not enter your password on a page reached through the email link
  • Do not approve any unexpected sign-in or multi-factor prompt
  • Do not ignore it without telling your IT team

Related scams to know

Common questions

How can I tell a real SharePoint share from a fake one?
Genuine shares appear when you open SharePoint or OneDrive directly. If a notice only works through an email link and asks you to log in again, it is worth treating with caution.
Why does the page ask me to log in again?
A convincing fake login page is how this scam captures your credentials. If you are already signed in to Microsoft, an unexpected request to log in again is a common warning sign.
Why are businesses targeted with this scam?
Work email logins can unlock company files, contacts and further attacks, so they are valuable to scammers. This is why SharePoint phishing is often aimed at staff at organisations.
I entered my password. What should I do?
Change your password right away from a trusted device, enable multi-factor authentication, and tell your IT or security team so they can review the account for unauthorised access.

Last reviewed June 2026 · Written & reviewed by the

Disclaimer: This page provides educational information only to help you recognise common scam patterns. It is not legal, financial, cybersecurity, or law enforcement advice, and it does not confirm whether any specific message, company, or person is genuine or fraudulent. When in doubt, contact the official organisation directly and report concerns to your local authorities.