Google Drive Shared File Phishing- How to Spot a Suspicious Share Before Opening It

 

Google Drive Shared File Phishing

- How to Spot a Suspicious Share Before Opening It

A Google Drive sharing notification can look trustworthy because the email itself may come through Google’s normal sharing system.

That is exactly what makes this type of phishing dangerous.

Google warns that scammers can abuse Drive collaboration features by sharing documents that contain harmful links or requests for personal information. Those links may also appear inside automatic Drive notification emails, which can make the message feel legitimate simply because Google delivered the notification.

The safest rule is simple:

Do not trust a shared file just because the notification came from Google. Check the sender, file name, context, and anything the document asks you to do.



 

1. Ask whether you were expecting the file

Start with the context.

Before opening a shared file, ask:

  • Do I know the person who shared it?
  • Was I expecting this document?
  • Does the file name match a real project, customer, invoice, or task?
  • Was the file mentioned in another conversation?

Be more cautious with unexpected titles such as:

  • Urgent Account Review
  • Payment Required
  • Security Alert
  • Confidential Document
  • Shared Invoice
  • Storage Warning

An unexpected file is not automatically malicious, but there is no reason to rush.

2. Check who actually shared the file

Look at the full email address of the person who shared the item.

Be careful when:

  • You do not recognize the sender
  • The address does not match the company name
  • The sender uses a strange or misspelled domain
  • The document supposedly comes from a coworker, but the address is external
  • The sender name looks familiar but the email address does not

A legitimate Google notification does not automatically make the person who created or shared the file trustworthy.

The notification system and the file owner are two different things.

3. Do not judge the file by the title alone

A phishing document can use a convincing name.

For example:

“2026 Salary Adjustment”

“Microsoft 365 Account Suspension”

“Final Invoice”

“Shared HR Document”

The title may be designed specifically to make you open the file quickly.

Check whether the document makes sense in your actual work or personal context before opening it.

4. Be careful with links inside the shared document

The shared Google Doc, Sheet, Slide, PDF, or other file may only be the first step.

Google specifically warns that scammers can share Drive documents containing harmful links that ask users to enter personal or confidential information.

Be cautious if the document tells you to:

  • Click a link to view the “real” file
  • Sign in again to Microsoft 365 or Google
  • Verify your account
  • Enter a password
  • Update payment information
  • Download another file or program

The fact that you opened the content through Google Drive does not make every external link inside the document safe.

5. Do not enter your password after following a suspicious link

This is one of the most important checks.

Google advises users not to enter account passwords after clicking a link in a message. If a link asks for your Google Account, Gmail, or another service password, go directly to the service through your normal trusted route instead.

For example:

Instead of clicking a Verify Google Account button inside a shared file, open your Google Account directly.

Instead of clicking Sign in to Microsoft 365, open Microsoft 365 through your usual bookmark or company portal.

A familiar logo is not proof that the login page is genuine.

6. Check links before clicking

On a computer, hover over a link and look at the actual destination.

Be cautious when:

  • The displayed text and destination URL do not match
  • The link goes to an unrelated domain
  • The domain contains subtle misspellings
  • The page redirects through unfamiliar websites
  • The destination suddenly asks for credentials

Google recommends checking the real web address before clicking suspicious links.

7. Verify the sender through another channel

If the file appears to come from someone you know but the request feels unusual, contact that person separately.

Use:

  • A known email thread
  • A normal workplace chat
  • A phone number you already have
  • Your company directory

For example:

“Did you just share a Google Drive file called ‘Updated Payment Details’ with me?”

Do not rely on the suspicious file or message itself for verification.

A 30-second Google Drive share checklist

Before opening or acting on an unexpected shared file, check:

Was I expecting this file?
Do I recognize the full sender address?
Does the file name make sense?
Does the document ask me to click another link or sign in?
Does the destination URL match the service it claims to be?
Can I verify the sender separately?

If one of these checks fails, stop before continuing.

How to report a suspicious shared file in Google Drive

Google Drive allows users to report shared files and folders as spam.

On a computer:

  1. Open Google Drive
  2. Go to Shared with me
  3. Right-click the suspicious file or folder
  4. Choose Block or report
  5. Select Report

You can also move unwanted shared items into the Spam folder. Google says reported items are moved to Spam, can be reviewed for policy violations, and are automatically removed after 30 days.

You do not need to keep opening a suspicious file just to investigate it.

How to report the phishing email in Gmail

If you received a suspicious sharing notification in Gmail:

  1. Open the message
  2. Click More
  3. Choose Report phishing

Google says reporting suspicious email helps its systems identify and respond to phishing and abuse.

What if you already entered your password?

If you opened the file but did not enter information, approve a login, or download anything, close the page and report the item.

If you entered your password on a suspicious website:

  • Change the affected password through the real service
  • Review recent account activity
  • Turn on 2-Step Verification if available
  • Report the incident to your IT or security team if it involves a work account
  • Check for unfamiliar account settings or access

Google recommends using 2-Step Verification and checking for suspicious activity when securing an account.

Final takeaway

The most important thing to remember is this:

A real Google Drive notification can still point to content shared by an untrusted person.

Do not judge the file only by the Google logo or the fact that it appeared in Drive.

Check:

Who shared it, whether you expected it, what the file asks you to do, and where any links actually lead.

That short check can help you avoid turning a simple shared-file notification into a stolen account.

신고하기

이 블로그 검색

오른쪽박스

왼쪽 광고