AWS Security and Compliance: UK GDPR, NCSC Guidance and Automated Assurance
Manage AWS UK GDPR compliance with NCSC guidance, Audit Manager, data sovereignty, and assurance.
A familiar Microsoft 365 login page appears after you click a shared-document invitation. You enter your password, approve an authentication request, and return to work. Nothing seems unusual. The page, however, was fake. An attacker may now have access to your email, cloud files, contacts, and connected business applications.
Phishing is particularly dangerous in cloud-based workplaces because one compromised account can provide access to several services. Employees must recognize more than badly written emails. Modern attacks can imitate trusted platforms, coworkers, suppliers, and IT support with alarming accuracy. This guide explains what phishing is, how cloud-focused attacks work, the warning signs to watch for, and what to do if you click a suspicious link.
A phishing attack is an attempt to trick someone into revealing sensitive information, approving access, transferring money, or installing malicious software by impersonating a trusted person or organization.
In a cloud work environment, attackers frequently imitate services such as Microsoft 365, Google Workspace, Dropbox, Slack, Microsoft Teams, DocuSign, Salesforce, online payroll systems, and cloud storage platforms. The objective is often to steal cloud account credentials or persuade the user to authorize a malicious application.
Once inside, an attacker may read email, download confidential files, reset passwords, impersonate the employee, or target other people in the organization.

Most phishing attacks use a simple formula: appear trustworthy, create pressure, and encourage an immediate action. For example, an employee may receive an email saying,
“Your Microsoft 365 password expires today. Sign in now to prevent account suspension.”
The link opens a page that looks almost identical to the genuine Microsoft login screen. The employee enters a username and password, but the information goes directly to the attacker. Cloud phishing can take several forms, and the attacker may use more than one method during the same campaign.
Attackers copy legitimate sign-in pages and place them on fraudulent websites. These pages are often promoted through fake security alerts, password-expiration notices, or document invitations. The branding may look convincing, but the website address and sign-in process may reveal that the page is not genuine.
A message may claim that a coworker, supplier, or customer has shared a file. Clicking “View Document” then leads to a fake login page or malicious download. Because cloud-based document sharing is common in modern workplaces, these messages can appear routine and may not immediately raise suspicion.
An attacker who already has a password may send repeated multi-factor authentication requests. The goal is to confuse, frustrate, or distract the account owner until one request is approved. Never approve a login request you did not initiate, even when repeated prompts make the request appear urgent.
Some attacks ask users to authorize a third-party application instead of requesting a password. The application may seek permission to read email, access cloud files, view contacts, or maintain ongoing account access. A user can therefore compromise an account by approving excessive permissions without ever revealing a password.
An attacker may impersonate an executive, supplier, or finance employee and request a payment, confidential document, or change to banking information. Some attackers use a genuinely compromised business account, which means a familiar email address alone should not be treated as proof that a request is legitimate.

Modern phishing messages may use correct spelling, professional branding, and specific information about your company. Examine the complete request instead of looking for one obvious mistake.
Be cautious when a message claims that your account will be suspended, your password expires immediately, or a payment requires urgent approval. Urgency is designed to prevent careful checking and encourage you to act before verifying the request.
Attackers register domains that resemble genuine company addresses. Check the complete sender and reply-to addresses, not only the displayed name. A small spelling change, extra character, or unusual domain may indicate impersonation.
Hover over a link to preview its destination. A button labeled “Open Microsoft Document” should not lead to an unrelated or misspelled domain. Remember that a padlock symbol only means the connection is encrypted. It does not prove that the website is legitimate.
Stop if a familiar cloud service suddenly asks you to sign in through an unusual page, download software, disable security settings, or provide information it does not normally request. Open the service through its official application or a trusted bookmark instead of continuing through the message.
Invoices, resumes, delivery notices, and financial reports are frequently used as phishing bait. Verify unexpected files through a trusted communication channel before opening them, particularly when the message creates urgency or comes from an unfamiliar address.
Treat unexpected requests for passwords, authentication codes, payroll records, customer information, payment changes, or confidential documents as suspicious. A manager or IT administrator should not need your password or MFA code.
Read every permission request before connecting an application to your cloud account. If a simple application requests access to all your email, contacts, and cloud files, cancel the process and contact IT. The permissions should be appropriate for the function the application claims to provide.
Use this five-step process:
Do not forward a suspected phishing email to coworkers unless your security policy instructs you to do so.

Awareness is important, but safe account practices provide additional protection. Employees should combine careful decision-making with strong authentication, unique passwords, controlled application access, secure devices, and prompt reporting.
MFA requires another form of verification beyond a password. It can prevent some account takeovers when an attacker has obtained a password, but users must still handle authentication requests carefully. Never approve a request you did not initiate.
Where available, use phishing-resistant authentication such as passkeys or physical security keys. Link phishing-resistant authentication to your passwordless authentication guide.
Never reuse a cloud account password on another website. If that website is breached, attackers may test the stolen password against your business accounts.
Use an organization-approved password manager to create and store unique credentials. A password manager can reduce password reuse without requiring employees to remember a different complex password for every service.
Periodically review which third-party applications can access your work account. Remove applications you no longer use, provided your organization allows employees to manage these connections.
Employees should also examine new application permission requests carefully. A tool should not receive access to email, files, contacts, or account information unless those permissions are necessary for its approved purpose.
Install required browser, application, and operating-system updates promptly. Updates help close vulnerabilities that malicious websites and files may attempt to exploit.
Employees should not delay security updates simply because the device appears to be working normally. A known vulnerability can remain exploitable even when there are no visible signs of a problem.
Reporting helps the security team block malicious senders, remove similar messages, warn other employees, and investigate whether anyone interacted with the attack. A message that you recognize as phishing may still deceive another employee.
For a broader understanding of passwords, data protection, identity security, and other cloud risks, read Cloud Security Fundamentals: A Complete Guide for Employees in 2026.
Clicking a suspicious link does not automatically mean your account has been compromised. What you do next matters.
Take these steps:
If you entered a password, report it immediately and change the password through the genuine cloud portal. If you approved an unexpected application or MFA request, state that clearly. The security team may need to revoke permissions or invalidate active sessions.
Unexpected urgency is one of the most common signs. Phishing messages often pressure users to sign in, open a file, make a payment, or provide information before they have time to verify the request.
Yes. Phishing can arrive through collaboration platforms, text messages, social media, shared documents, and cloud application notifications. Employees should verify unusual requests regardless of the communication channel used.
No. MFA provides important protection, but attackers may try to steal verification codes, trigger repeated approval requests, or persuade users to authorize malicious applications. Phishing-resistant authentication can provide stronger protection where it is available.
Avoid using the message link. Open the service through its official application, a trusted bookmark, or a manually entered address. Check the complete domain before entering credentials or approving access.
Yes. Reporting can help the security team block the attack, remove similar messages, identify affected users, and protect other employees.
A professional-looking message is not necessarily trustworthy. Before opening a shared file, entering cloud credentials, approving an MFA request, or authorizing an application, pause and verify what you are being asked to do.
These small habits can prevent account takeovers, data exposure, financial fraud, and wider business disruption. Employees who report suspicious messages quickly also help security teams protect everyone else in the organization.
To understand phishing alongside password security, access control, data protection, and other everyday risks, explore our Cloud Security Fundamentals For All Employees course. It provides a structured and practical way to strengthen the security decisions employees make every day.