All systems operational · Ormskirk, North West England

New Phishing Scam Targets SharePoint and OneDrive

Microsoft has warned of a phishing technique that exploits SharePoint and OneDrive to bypass security filters. Here is how it works and how to protect your business.

Using Trusted Platforms Against You

Microsoft has issued a warning about a phishing technique that uses SharePoint and OneDrive to deliver malicious content. The approach exploits the fact that files shared from these platforms are generally considered safe, allowing attackers to bypass security filters that would catch links to unknown external sites.

The attack begins with compromised user accounts, obtained through credential theft or purchase on the dark web. Once inside a cloud storage account, attackers upload files that mimic genuine business documents, such as a Microsoft 365 login page. They set these files to view-only or restrict access to specific recipients to avoid raising suspicion. When a colleague opens the file and follows the link inside, they land on a convincing fake login page and unknowingly hand over their credentials.

Why This Technique Is Effective

Security tools tend to trust links that come from Microsoft’s own cloud services. A file shared from SharePoint or OneDrive is less likely to trigger warnings than a link to an unknown domain. That trust is what attackers are exploiting. The file itself may look entirely genuine, with familiar Microsoft branding and formatting, giving no indication that anything is wrong.

Once one account is compromised, attackers can use it to send further phishing files to contacts, spreading the attack through what appears to be a trusted internal source.

How to Protect Your Business

Verify unexpected file shares

If a shared file arrives unexpectedly, even from a known contact, confirm with the sender through a separate channel before opening it. A quick phone call or direct message takes seconds and removes the risk. Do not click links inside a shared document to log in to any service.

Enable multi-factor authentication

MFA prevents stolen credentials from being used to access accounts. Even if an attacker obtains a password, they cannot log in without the second factor. For Microsoft 365 accounts in particular, MFA is an essential control.

Keep security software current

Security tools are updated regularly to recognise new attack patterns. Keeping endpoint protection and email security software up to date ensures your defences reflect the latest known threats, including evolving cloud-based phishing techniques.

Train staff on cloud-based phishing

Many employees understand email phishing but are less aware that files shared from cloud storage can also be malicious. Specific awareness of this technique, and the habit of verifying unexpected shares, closes a gap that technical controls alone cannot address.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.