Blog/Phishing

Cloud Storage Links in Phishing Emails

Phishers host fake documents and sign-in pages on real cloud storage and form services, so links start with trusted domains. How this works and how to judge a shared link.

CyberWatch AI1 October 2026 · 2 min read
A person holding a mug in front of an open laptop

We tell people to check where a link goes. Phishers adapted: they now host their traps on well-known cloud storage, document and form services. The link starts with a domain you trust, so it passes a quick check and many filters.

How it works

  1. The attacker creates a free account on a cloud storage, document or form service.
  2. They upload a file or create a page, such as a PDF with a "View document" button or a form asking for a password.
  3. They share it by email, often from a compromised account. See document share phishing.
  4. The file leads you on to a fake sign-in page or malware download elsewhere.

How to judge a shared link

  • Were you expecting it? If not, ask the sender through another channel.
  • Who owns the file? Shared files show the owner's name or email.
  • Does it send you elsewhere? A document that only contains a button to "view" or "sign in" is a red flag.
  • Does it ask for a password? Forms and documents should never ask for your account password.

A trusted domain in the link is not enough. Judge the file, the sender and what it asks you to do.

If you engaged with one

Unsure about a shared file? Paste the email into CyberWatch AI Scan for a free check.

For more, see how phishing works in our complete guide.

Frequently asked questions

If a link is on a real cloud service, is it safe?

Not necessarily. Anyone can create an account on a cloud or form service and share a file or page that leads to phishing.

What should I look for?

Whether you expected the file, who shared it, and whether the file sends you on to a sign-in page or download elsewhere.

Can I report malicious shared files?

Yes. Most cloud and form services have a 'report abuse' option on shared files and pages.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  3. Report a phishing page, Google Safe Browsing
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.