The fake cloud storage or M365 alert
A notice claiming a document was shared with you or your storage quota is full, leading to a fake Microsoft or Google login page.
The scenario
This is an illustrative training example, not a real notification from Claro, Microsoft, or Google. In this scenario the email mimics a cloud storage or Microsoft 365 alert, claiming a document has been shared with you or that your storage quota is full. It includes a 'View Document' or 'Upgrade Storage' button that leads to a fake sign-in page.
The pretext borrows from something you see constantly at work. Shared-file notifications and storage warnings are genuinely common, so the message does not stand out. It presents a simple next step, click to view or click to free up space, that feels like part of your normal routine rather than a decision worth pausing over.
It arrives in your work inbox looking like an automated system message, sometimes with a colleague's name attached to the 'shared' file to make it personal. The layout, icons, and wording are easy to copy convincingly, so nothing about the first glance suggests anything is wrong.
It is convincing because the fake login page is the real payoff. It can look identical to the genuine Microsoft or Google sign-in screen, so when you enter your email and password out of habit, you hand your credentials straight to the attacker. Because so many services share one cloud login, a single slip can expose email, files, and connected apps at once.
Red flags to spot
A sign-in page that asks for your password on a domain that is not Microsoft's or Google's
The address bar shows a lookalike domain, the clearest sign of a fake login page.
A vague sender for the 'shared' document, such as 'A colleague' or a generic team name
Real sharing notifications usually name the specific person who shared the file.
An urgent storage-full warning threatening loss of access to your files
Storage alerts are rarely framed as an immediate threat that requires clicking a link right away.
A button that leads to a link not matching your organization's actual cloud domain
Hovering before clicking reveals a different domain from your company's real M365 or Google Workspace tenant.
A sign-in prompt appearing even though you are already logged into your cloud account
If you are signed in, a genuine shared file opens directly, so an unexpected login page is suspicious.
A document title that is generic or unrelated to your actual work
Attackers use vague names like 'Invoice' or 'Report' because they cannot know what files you truly expect.
The lesson
Open shared documents and storage alerts by going directly to your cloud storage app or typing the address yourself, not through a link in an email. Before entering any password, check that the sign-in page is on the genuine Microsoft or Google domain, and be wary of any login prompt that appears when you are already signed in. If something looks off, close the page and report the email to your security team.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
Change your password immediately from a trusted device by going directly to your cloud provider, and turn on multi-factor authentication if it is not already active. Then tell your IT or security team so they can review sign-in activity and secure connected apps. Acting quickly limits how far the attacker can reach.
Related pages
Bank Account Verification
An email or SMS claiming to be from a bank warns of a suspicious transaction and asks you to verify your account through a fake login link.
Learn moreFake DJP Tax Refund Notice
A message impersonating the Directorate General of Taxes (DJP) claims you have a refund waiting or overdue tax to pay, and pushes you to click a link before a deadline.
Learn moreFake BPJS Benefit Reactivation Message
A message posing as BPJS Kesehatan or Ketenagakerjaan warns that your benefits will be suspended unless you 'verify' your data through a link.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo