Cloud / M365

The fake cloud storage or M365 alert

A notice claiming a document was shared with you or your storage quota is full, leading to a fake Microsoft or Google login page.

The scenario

This is an illustrative training example, not a real notification from Claro, Microsoft, or Google. In this scenario the email mimics a cloud storage or Microsoft 365 alert, claiming a document has been shared with you or that your storage quota is full. It includes a 'View Document' or 'Upgrade Storage' button that leads to a fake sign-in page.

The pretext borrows from something you see constantly at work. Shared-file notifications and storage warnings are genuinely common, so the message does not stand out. It presents a simple next step, click to view or click to free up space, that feels like part of your normal routine rather than a decision worth pausing over.

It arrives in your work inbox looking like an automated system message, sometimes with a colleague's name attached to the 'shared' file to make it personal. The layout, icons, and wording are easy to copy convincingly, so nothing about the first glance suggests anything is wrong.

It is convincing because the fake login page is the real payoff. It can look identical to the genuine Microsoft or Google sign-in screen, so when you enter your email and password out of habit, you hand your credentials straight to the attacker. Because so many services share one cloud login, a single slip can expose email, files, and connected apps at once.

Red flags to spot

A sign-in page that asks for your password on a domain that is not Microsoft's or Google's

The address bar shows a lookalike domain, the clearest sign of a fake login page.

A vague sender for the 'shared' document, such as 'A colleague' or a generic team name

Real sharing notifications usually name the specific person who shared the file.

An urgent storage-full warning threatening loss of access to your files

Storage alerts are rarely framed as an immediate threat that requires clicking a link right away.

A button that leads to a link not matching your organization's actual cloud domain

Hovering before clicking reveals a different domain from your company's real M365 or Google Workspace tenant.

A sign-in prompt appearing even though you are already logged into your cloud account

If you are signed in, a genuine shared file opens directly, so an unexpected login page is suspicious.

A document title that is generic or unrelated to your actual work

Attackers use vague names like 'Invoice' or 'Report' because they cannot know what files you truly expect.

The lesson

Open shared documents and storage alerts by going directly to your cloud storage app or typing the address yourself, not through a link in an email. Before entering any password, check that the sign-in page is on the genuine Microsoft or Google domain, and be wary of any login prompt that appears when you are already signed in. If something looks off, close the page and report the email to your security team.

These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.

Frequently asked questions

  • Change your password immediately from a trusted device by going directly to your cloud provider, and turn on multi-factor authentication if it is not already active. Then tell your IT or security team so they can review sign-in activity and secure connected apps. Acting quickly limits how far the attacker can reach.

Run these patterns as real simulations

Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.

Request a demo