Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Someone shared a document you were not expecting. You do not have to open it

An invoice, HR file or urgent review invitation can look like a routine cloud notification. Learn how to check it without clicking blindly.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
7 September 2026
READING TIME
7 min read
TOPIC
Human Security
Someone shared a document you were not expecting. You do not have to open it

An email says that somebody has shared a document with you. Its title mentions an invoice, a salary change or urgent comments on a contract. It resembles the cloud notifications people handle every day, so opening it feels like a routine part of work.

An unexpected invitation is not automatically an attack. Somebody may have mistyped an address, a colleague may have forgotten to tell you about the file or a client may be using a new account. But shared documents are also a convenient story for stealing passwords. You do not have to guess which explanation is true; you can check the context safely.

Do not start with the button in the message

Instead of selecting “Open document”, launch the familiar app or type the address of your work drive yourself. Check the section containing items shared with you. If the document exists, that still does not prove it is relevant or safe, but you have avoided a link that could lead to an imitation sign-in page.

Check the owner’s name, account address and document title. If it supposedly comes from a colleague, ask them through a known channel: work chat, a telephone call or in person. Do not reply to a suspicious email, because the answer may go straight to whoever sent the lure.

A short question is enough: “Did you just share a document with this name?” A genuine sender can explain the context. An attacker hopes that an invoice, pay rise or urgent signature will replace that check.

A genuine logo does not prove genuine intent

The notification may genuinely come from a popular service while pointing to a file created by a stranger. The document, its title or a comment can hold the next malicious link. A Microsoft or Google logo may identify the platform, not the honesty of the person who owns the file.

Stop if the page asks again for your password, a sign-in code, phone number or permission for an unfamiliar app. Do not enter anything. Close the tab and return through your bookmark, official app or the address you use every day.

Report the invitation without opening the document

Mark the suspicious email as phishing in your mail application. If the item also appears in the list of shared files, use the service’s spam or abuse report. At work, tell IT or security and provide the file name, sender and approximate time. Avoid forwarding a live link to the whole team as a warning.

If the invitation was simply a mistake, you still do not need to inspect its contents. Remove your access or ask the owner to remove your address. Somebody else’s document may contain information you were never meant to see.

If you already entered a password

Open the genuine service from your own bookmark or app and change the password immediately. End other active sessions, review recent sign-ins and make sure multi-factor authentication and recovery details have not been changed. If the page requested permission for an app, tell IT: changing the password alone may not revoke access you approved.

At work, describe exactly what happened: which link you opened, what information you entered and whether you approved a code or notification. A fast, honest report gives the team a chance to terminate the session, block the message for other people and see whether the account was used.

What the sources say and what Breachroad recommends

Microsoft uses a fake cloud-hosted document as an example of phishing designed to steal a password and recommends reporting suspicious messages. Google separately explains how to report a shared Drive file as spam without engaging with its contents.

Breachroad recommends separating two questions: “Is this a real notification from the platform?” and “Do I know the owner and expect this document?”. Only when both answers are yes do you have useful context for proceeding.

For more examples, read Phishing in 2026: why training alone is not enough. If your team needs practical habits for everyday work, explore our security awareness training.

SHARE / COPY