{"success":true,"data":{"id":"googledrive-share-cross-domain","label":"Fake Google Drive / Google Docs shared-document notification sent from a non-Google domain — credential-harvest cross-domain phish; the \"open in Drive\" CTA leads to a lookalike Google login page. Real Google Drive sharing mail originates from google.com / drive.google.com / docs.google.com only.","description":"Fake Google Drive / Google Docs / Google Sheets shared-document or \"invited you to edit\" notification sent from a non-Google sending domain (From / Reply-To / link domains do not align with google.com / drive.google.com / docs.google.com) directing the recipient to a \"view document\" or \"open in Drive\" link — credential-harvest cross-domain phish targeting Google Workspace credentials. Real Google Drive sharing communications originate exclusively from google.com / drive.google.com / docs.google.com with DMARC-aligned signing; shared-link CTAs always terminate at *.google.com / *.googleusercontent.com, never at third-party domains. Google Drive impersonation is a top-3 file-sharing phishing lure per Vade 2024 Phishers Favorites and Cofense 2024 PDC. Distinct from onedrive-share-cross-domain (Microsoft) and dropbox-share-cross-domain (Dropbox) — this targets the Google Drive / Google Docs / Google Sheets / invited-you-to-edit / open-in-drive pretext with off-domain href. Detection: Google Drive / Docs / Sheets brand vocabulary + sender or link domain ≠ google.com / drive.google.com / docs.google.com + no DMARC alignment. Trash score: +4. Source: GC1-R32; Vade 2024 Phishers Favorites; Cofense 2024 PDC quarterly report; Google Workspace anti-phishing guidance.","tier":"warning","category":"other","isThin":false}}