Shared Document and E-Signature Phishing
"A document has been shared with you" and "Please sign this contract" are favourite phishing lures. How fake sharing and e-signature notices work and how to check them.

Sharing files and signing documents online is routine at work, which makes it perfect cover for phishing. A notice says someone shared a document or needs your signature. You click, see a familiar sign-in page, and enter your password to view it. There was no document; the page was fake.
Common versions
- "[Name] has shared a document with you" with a "View document" button.
- "Please review and sign: Contract_2026.pdf".
- "You have received a secure file" from an encrypted-sharing service.
- Voicemail or fax notices that lead to a "document". See fake voicemail emails.
- Real file-sharing services used to host the phishing page. See cloud storage links in phishing.
- An unexpected file about payments.
- The "Open" link leads to a sign-in page on an unfamiliar address.
How to check
- Open the file-sharing or e-signature service yourself and look for the file.
- Ask the sender through another channel if you were not expecting it.
- If you clicked, check the web address before entering anything.
- Notice if your password manager does not offer to fill in your password.
You should rarely need to re-enter your password to view a shared file if you are already signed in. An unexpected sign-in prompt is a warning sign.
Got a sharing notice? Paste it into CyberWatch AI Scan for a free check.
For more, see how to recognise phishing in our complete guide.
Frequently asked questions
How can I tell a real sharing notice?
Open the file-sharing app or service yourself and look for the file under 'Shared with me'. If it is not there, the email was likely fake.
Why does the login page look exactly like the real one?
Attackers copy real sign-in pages. The web address is the giveaway, and a password manager will not autofill there.
The share came from a colleague's real address. Is it safe?
Not necessarily. Compromised accounts are used to send fake shares. If unexpected, ask the colleague through another channel.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency


