{"success":true,"data":{"id":"onedrive-share-cross-domain","label":"Fake Microsoft OneDrive / SharePoint shared-document notification sent from a non-Microsoft domain — credential-harvest cross-domain phish; the \"view document\" CTA leads to a lookalike Microsoft login page. Real OneDrive / SharePoint sharing mail originates from microsoft.com / onedrive.live.com / sharepoint.com only.","description":"Fake Microsoft OneDrive / SharePoint shared-document or shared-folder notification sent from a non-Microsoft sending domain (From / Reply-To / link domains do not align with microsoft.com / onedrive.live.com / sharepoint.com / office.com) directing the recipient to a \"view document\" or \"open shared folder\" link — credential-harvest cross-domain phish targeting Microsoft 365 tenant credentials. Real OneDrive / SharePoint sharing communications originate exclusively from microsoft.com / onedrive.live.com / *.sharepoint.com tenant subdomains with DMARC-aligned signing; shared-link CTAs always terminate at microsoft.com or *.sharepoint.com, never at third-party domains. OneDrive / SharePoint impersonation is the #1 enterprise file-sharing phishing lure per Microsoft Digital Defense Report 2024 because shared-document notifications are routine in M365 tenants. Distinct from dropbox-share-cross-domain (Dropbox) and googledrive-share-cross-domain (Google) — this targets the OneDrive / SharePoint / shared-with-you / view-document pretext with off-domain href. Detection: OneDrive / SharePoint brand vocabulary + sender or link domain ≠ microsoft.com / onedrive.live.com / sharepoint.com + no DMARC alignment. Trash score: +4. Source: GC1-R32; Microsoft Digital Defense Report 2024; APWG file-share phishing tracker 2025; CISA Microsoft 365 phishing advisory.","tier":"warning","category":"other","isThin":false}}