Work phishing emails: shared files, payroll and passwords
Before you click, read the sender's domain. Outside domains asking you to sign in are the most common attack at work.
Test yourself: how many would you spot?no-reply@sharepoint-docs-online.com
Priya Sharma has shared "Salary_Revision_2026.xlsx" with you. Sign in with your work account to view. Link expires in 24 hours.
SCAM
How it works
- An email copies a trusted tool: file sharing, HR, IT or a courier.
- A link, QR code or .html file opens a fake login page.
- Your password, and sometimes MFA code, goes to the attacker.
Red flags
- Outside or lookalike domains ('m1crosoft', 'yourcompany-support.net')
- Tempting files like salary sheets, or 'act today' deadlines
- QR codes and .html attachments
Stay safe
- Open shared files from your own drive or app
- Make HR and payroll changes only in the official portal
- Use the report-phishing button or tell IT
Already happened? Act fast
- Call 1930National Cyber Crime Helpline. The sooner you call, the better the chance of stopping the money.
- cybercrime.gov.inFile an online complaint. Keep screenshots and transaction IDs.
- Call your bankUse the number on your card to block cards, UPI or the account.
- Report on ChakshuReport fraud calls, SMS and WhatsApp messages at sancharsaathi.gov.in.
Questions
Why do attackers use QR codes?
Email filters often can't read QR codes, and phones have fewer protections. Treat QR codes in emails with suspicion.
Scam