MailGuard 9 October 2026, 15:17:20 AEDT 7 MIN READ

A new “Secure Folder” Auth phishing scam targets Microsoft accounts

 

A new phishing campaign is impersonating secure‑document platforms, using a fabricated “shared folder” workflow to lure recipients into a multi‑step web flow designed to trick them into authorising a malicious third‑party app with full access to their Microsoft account. 

What the Scam Looks Like

The email itself is deliberately ordinary. It arrives with a neutral operational heading such as “Auto‑Receipt || The requested submittals for this quote Replacements READY FOR REVIEW”, styled to resemble a routine document‑completion or e‑signature notification.

The body advises the recipient that a document is ready to review and sign, accompanied by a blue View & Complete Item button. A “Document Invite” reference reinforces the illusion of legitimacy.

Docusign - 1-01

Example phishing content shown using document‑workflow branding. Not affiliated with any legitimate provider.

Behind the branding, the sender details tell a different story:

  • Display name: RecordsTeam
  • Display address: kensuke.n(at)nakabayashi-co.com
  • Sending address: kensuke.n(at)nakabayashi-co.com

None of these align with legitimate document‑signing or file‑sharing infrastructure, but the email is styled convincingly enough that a busy staff member could easily miss the mismatch.

Inside the phishing flow

Clicking the button leads to a multistage redirect chain designed to appear trustworthy:

  • link(dot)edgepilot(dot)com
  • secure-web(dot)cisco(dot)com
  • artemisabeach[dot]com /(dot)well-known__e71c118/pki-validation/gqazbvcb

By routing through recognised services, attackers aim to bypass basic checks and reduce suspicion.

Step 1:  Fake Dropbox “Shared Folder” page 

The first landing page impersonates Dropbox, claiming that a secure folder has been shared and prompting the user to Access Folder to view a file such as Client_Assets_2026.zip. .

Docusign - 4-01Example phishing content shown using Dropbox branding. Not affiliated with Dropbox. 

Clicking Access Folder opens a new tab to:

  • musairkompresor[dot]com /uploads/wilderfrress/
  • which then opens avittti[dot]com /injabazmishelinktoon

Each step is designed to feel like a normal progression through a secure document‑access flow.

Step 2:   Fake “Secure Document Access” verification page  

The next page impersonates a DocuSign‑style secure‑document portal. It presents an encrypted file and instructs the user to copy a code, click Verify & Paste, and sign in with a Microsoft account. 

Docusign - 2-01Example phishing content shown using DocuSign‑style branding. Not affiliated with DocuSign. 

This is the critical pivot point. The user believes they are performing an extra security step. In reality, they are being guided into an OAuth device‑code flow that will grant attackers persistent access to their Microsoft account. 

Step 3:  Genuine Microsoft login page used deceptively  

Clicking either button launches a legitimate Microsoft endpoint at login.microsoftonline.com, displaying:

  • “Enter code to allow access”
  • A field labelled Code
  • A blue Next button

Docusign - 3-01Example phishing content shown using Microsoft branding. Not affiliated with Microsoft.

Once the user enters the code and signs in, the malicious application receives tokens granting long‑term access to emails, files, contacts, SharePoint, OneDrive, and other Microsoft 365 data. 

Why this scam is worth flagging to your team

  • Several details make this campaign more dangerous than a typical credential‑phishing attempt:

  • It grants full account access without stealing a password. OAuth‑based attacks bypass traditional login‑page training.

  • The pretext is mundane and plausible. Shared folders, encrypted files, and document‑completion workflows are routine business tasks.

  • The staged verification steps feel authentic. Copy‑and‑paste codes, multi‑page flows, and “Waiting for verification…” messages mimic legitimate secure‑document experiences.

  • The branding is familiar and low‑friction. Dropbox, DocuSign‑style layouts, and genuine Microsoft login screens reduce scrutiny.

  • The redirect chain uses legitimate services. link.edgepilot.com and secure-web.cisco.com make the click path appear safe.

  • For organisations whose staff regularly handle shared folders, approvals, or document workflows, this type of scam has implications far beyond individual compromise. A single OAuth consent can provide attackers with persistent access to business‑critical data.

Stay Safe, Know the Signs

MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.

Avoid emails that:

  • Aren’t addressed to you personally.
  • Are unexpected and urge immediate action.
  • Contain poor grammar or miss crucial identifying details.
  • Direct you to a suspicious URL that isn’t associated with the genuine company.

Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.

One Email Is All That It Takes   

All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.     

For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters!  Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.  

Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.  

Keep Informed with Weekly Updates

 

RELATED ARTICLES