Cloud Storage Links in Phishing Emails
Phishers host fake documents and sign-in pages on real cloud storage and form services, so links start with trusted domains. How this works and how to judge a shared link.

We tell people to check where a link goes. Phishers adapted: they now host their traps on well-known cloud storage, document and form services. The link starts with a domain you trust, so it passes a quick check and many filters.
How it works
- The attacker creates a free account on a cloud storage, document or form service.
- They upload a file or create a page, such as a PDF with a "View document" button or a form asking for a password.
- They share it by email, often from a compromised account. See document share phishing.
- The file leads you on to a fake sign-in page or malware download elsewhere.
How to judge a shared link
- Were you expecting it? If not, ask the sender through another channel.
- Who owns the file? Shared files show the owner's name or email.
- Does it send you elsewhere? A document that only contains a button to "view" or "sign in" is a red flag.
- Does it ask for a password? Forms and documents should never ask for your account password.
A trusted domain in the link is not enough. Judge the file, the sender and what it asks you to do.
If you engaged with one
- Entered a password: change it and sign out of all sessions. See entered your password on a phishing page.
- Downloaded something: do not open it, and tell IT.
- Report the file to the hosting service.
Unsure about a shared file? Paste the email into CyberWatch AI Scan for a free check.
For more, see how phishing works in our complete guide.
Frequently asked questions
If a link is on a real cloud service, is it safe?
Not necessarily. Anyone can create an account on a cloud or form service and share a file or page that leads to phishing.
What should I look for?
Whether you expected the file, who shared it, and whether the file sends you on to a sign-in page or download elsewhere.
Can I report malicious shared files?
Yes. Most cloud and form services have a 'report abuse' option on shared files and pages.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Report a phishing page, Google Safe Browsing


