Real platform, unsafe content
Attackers can share a file from a real Google account, place a malicious link inside the document, and let Google send the notification. Traditional sender checks may look clean.
Before opening
- Ask whether you know the person who shared it.
- Confirm through a separate channel if the document was unexpected.
- Open Google Drive directly and inspect the owner’s full address.
- Do not follow login, payment, download, or phone-number instructions inside an unfamiliar file.
If you already clicked
If you only viewed a Google document, the risk may be limited. If you entered credentials, approved an application, downloaded a file, or ran anything, disconnect and contact IT immediately.
