A new phishing campaign is impersonating secure‑document platforms, using a fabricated “shared folder” workflow to lure recipients into a multi‑step web flow designed to trick them into authorising a malicious third‑party app with full access to their Microsoft account.
What the Scam Looks Like
The email itself is deliberately ordinary. It arrives with a neutral operational heading such as “Auto‑Receipt || The requested submittals for this quote Replacements READY FOR REVIEW”, styled to resemble a routine document‑completion or e‑signature notification.
The body advises the recipient that a document is ready to review and sign, accompanied by a blue View & Complete Item button. A “Document Invite” reference reinforces the illusion of legitimacy.
Example phishing content shown using document‑workflow branding. Not affiliated with any legitimate provider.
Behind the branding, the sender details tell a different story:
None of these align with legitimate document‑signing or file‑sharing infrastructure, but the email is styled convincingly enough that a busy staff member could easily miss the mismatch.
Clicking the button leads to a multistage redirect chain designed to appear trustworthy:
By routing through recognised services, attackers aim to bypass basic checks and reduce suspicion.
Step 1: Fake Dropbox “Shared Folder” page
The first landing page impersonates Dropbox, claiming that a secure folder has been shared and prompting the user to Access Folder to view a file such as Client_Assets_2026.zip. .
Clicking Access Folder opens a new tab to:
Each step is designed to feel like a normal progression through a secure document‑access flow.
Step 2: Fake “Secure Document Access” verification page
The next page impersonates a DocuSign‑style secure‑document portal. It presents an encrypted file and instructs the user to copy a code, click Verify & Paste, and sign in with a Microsoft account.
This is the critical pivot point. The user believes they are performing an extra security step. In reality, they are being guided into an OAuth device‑code flow that will grant attackers persistent access to their Microsoft account.
Step 3: Genuine Microsoft login page used deceptively
Clicking either button launches a legitimate Microsoft endpoint at login.microsoftonline.com, displaying:
Once the user enters the code and signs in, the malicious application receives tokens granting long‑term access to emails, files, contacts, SharePoint, OneDrive, and other Microsoft 365 data.
Why this scam is worth flagging to your team
Several details make this campaign more dangerous than a typical credential‑phishing attempt:
It grants full account access without stealing a password. OAuth‑based attacks bypass traditional login‑page training.
The pretext is mundane and plausible. Shared folders, encrypted files, and document‑completion workflows are routine business tasks.
The staged verification steps feel authentic. Copy‑and‑paste codes, multi‑page flows, and “Waiting for verification…” messages mimic legitimate secure‑document experiences.
The branding is familiar and low‑friction. Dropbox, DocuSign‑style layouts, and genuine Microsoft login screens reduce scrutiny.
The redirect chain uses legitimate services. link.edgepilot.com and secure-web.cisco.com make the click path appear safe.
For organisations whose staff regularly handle shared folders, approvals, or document workflows, this type of scam has implications far beyond individual compromise. A single OAuth consent can provide attackers with persistent access to business‑critical data.
Stay Safe, Know the Signs
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.