Beware of SharePoint Phishing Campaigns

Summary

Employees may receive phishing emails that appear to be SharePoint or OneDrive file shares. These emails attempt to steal login credentials. Do not click links or open attachments—report the message using the Phish Alert Button and delete it.

Body

What Is a SharePoint Phishing Attachment?

Some phishing emails are designed to look like SharePoint or OneDrive document shares sent to employees.
These messages often appear to come from:

  • A coworker
  • A supervisor
  • A campus department
  • A known external partner

The goal of these emails is to trick employees into:

  • Opening a fake document
  • Clicking a malicious link
  • Entering their university login credentials

These attacks specifically target employee accounts, which often have access to sensitive systems or data.

What a SharePoint Phishing Email May Look Like

You may see subject lines or messages such as:

  • “<Name> shared a document with you”
  • “Action required: File awaiting your review”
  • “Urgent: Please open before deadline”

Common warning signs:

  • You were not expecting a document
  • The message creates urgency or pressure
  • The sender name looks familiar, but the email address is unusual
  • The link asks you to sign in to view the file, even though you are already signed in
What NOT to Do

Do not:

  • Open the attachment
  • Click the SharePoint or OneDrive link
  • Enter your username or password
  • Reply to the sender
  • Forward the message to coworkers

Interacting with the message can put your employee account at risk.

What TO DO Instead

Report the email

  • Use the Phish Alert Button (PAB) in Outlook to report the email.
  • Or forward the suspicious email to informIT@ncat.edu

This sends the message directly to the Information Security Office for review and action.

If You Already Clicked the Link or Signed In

If you:

  • Clicked the link
  • Opened the attachment
  • Entered your employee credentials

Take action immediately:

  1. Ensure changes to your account information such as MFA registered devices has not been modified
  2. Change your password right away using the self service portal, if you're unable to complete this process continue to step 3: https://passwordreset.microsoftonline.com/
  3. Contact the Service Desk or submit a compromised account security ticket 
  4. Report the message using the Phish Alert Button

Prompt reporting helps limit impact to your account and other employees.

Why This Matters for Employees

Employee accounts are frequently targeted because they may provide access to:

  • Internal systems
  • Financial or HR data
  • Shared departmental files
  • Administrative tools

Reporting phishing attempts helps ITS:

  • Protect employee accounts
  • Remove similar messages across campus
  • Improve campus‑wide email security protections

You will not be penalized for reporting a suspicious email.

Details

Details

Article ID: 20161
Created
Tue 4/21/26 11:23 AM
Modified
Tue 8/18/26 3:55 PM
Shared Article Departments
Not A Shared Article

Attachments

;