{"success":true,"data":{"id":"doc-share-phishing","label":"Document-share phishing — fake OneDrive/SharePoint/Google Drive/Dropbox share + sign-in-to-view credential harvest","description":"Body contains a fake document-share notification — a branded platform reference (OneDrive, SharePoint, Google Drive, Dropbox, Adobe, DocuSign) combined with \"shared a document/file with you\" language, OR the generic \"has shared a file with you\" phrasing attackers copy verbatim from legitimate notifications. Paired with a credential-harvest hook: \"sign in to view\", \"verify your identity to open\", click-to-view + time-limited \"link expires in N hours\", or a \"secure document\" wrapper. This is one of the highest-volume corporate phishing categories per Cofense and Proofpoint 2024 reports. The harvest page typically mimics a Microsoft or Google sign-in form so the user types real credentials into it. Legitimate share notifications never ask you to sign in from a link embedded in the email — they bounce you to the platform's own SSO page via its first-party domain.","tier":"danger","category":"phishing","isThin":false}}