AWS Security and Compliance: Detecting Misconfigurations and Responding to Cloud Incidents
Detect AWS misconfigurations and incidents with monitoring, Security Hub, CloudTrail, GuardDuty, and response.
Phishing remains one of the most common ways criminals attempt to gain access to cloud accounts. Instead of attacking a cloud platform directly, they manipulate users into revealing passwords, approving unexpected sign-in requests or opening convincing fake login pages.
Following cloud security best practices helps everyday users recognise these attempts before sensitive information is exposed. This article focuses on phishing prevention, fake login detection and safer responses. For wider advice about passwords, file sharing, devices and data privacy, read our cloud security best practices guide.
Phishing is a form of deception in which an attacker pretends to be a trusted organisation, colleague or cloud provider. The message may arrive through email, text, social media, a collaboration platform or even a QR code. It often creates urgency by claiming that an account will be suspended, a payment has failed or a shared document requires immediate attention.
The link may lead to a fake login page designed to resemble Microsoft 365, Google Workspace, Dropbox or another familiar service. When the user enters a password, the attacker captures it. Some pages also request multi-factor authentication codes, recovery details or permission to connect an unsafe application.
According to the UK National Cyber Security Centre’s phishing guidance, phishing messages may direct users to websites that steal passwords, obtain sensitive information or deliver malicious software.

A fake login page may copy familiar colours, wording and layouts, so appearance alone cannot confirm that it is genuine. Before entering any information, check the full website address carefully. Misspelled company names, added words, unusual characters and unfamiliar domains are warning signs.
Unexpected urgency should also raise concern. A message that threatens immediate account closure or pressures you to approve a sign-in may be trying to prevent careful checking. Other warning signs include unusual greetings, unexpected attachments, requests for verification codes and shared-file notifications you were not expecting.
Do not rely only on the sender’s displayed name. Email addresses can be imitated, and compromised accounts may send believable messages from real contacts. If a colleague unexpectedly asks you to open a cloud document or change a payment, confirm the request through a separate trusted channel.

One cloud identity may provide access to email, files, calendars, contact lists and workplace applications. A compromised account can therefore expose more than one service. Attackers may also use the account to send convincing phishing messages to colleagues or customers.
Users should open important cloud services through a saved bookmark or official application instead of an unexpected message. They should never share passwords, recovery codes or MFA codes. Suspicious messages should be reported promptly, even when no link was opened.

Recognising fake messages becomes easier when you know which warning signs to check and how to respond without panic. The Cloud Security Awareness for Everyday Cloud Users course covers phishing emails, fake login pages, malicious QR codes, MFA requests and account-incident reporting through clear, workplace-relevant guidance.
Recognising a suspicious message is important, but phishing prevention also depends on safer everyday habits. Users should slow down whenever a message creates urgency, requests confidential information or asks them to complete an unexpected login. A short verification can prevent a much larger cloud security incident.
Avoid signing in through links contained in unexpected emails or messages. Instead, open the official cloud application, use a saved bookmark or type the known website address into the browser. If the account genuinely requires attention, the same notification should normally appear inside the official service.
This habit is particularly useful for shared-document messages. Criminals may create fake notifications claiming that a colleague has shared an invoice, report or confidential file. Contact the supposed sender through a trusted channel when the document is unexpected.
The visible link text may not match the destination. On a computer, hovering over a link can reveal its address, but users should still avoid opening it when they are uncertain. Shortened links, unfamiliar domains and small spelling changes can conceal fake login pages.
A padlock symbol does not prove that a website is genuine. It only shows that the connection between the browser and that site is encrypted. A phishing website can also use encryption, so users must check the complete domain name.
Multi-factor authentication can reduce the risk created by a stolen password, but users must treat every approval request carefully. Never approve an MFA notification that you did not initiate. Repeated requests may be an attempt to pressure you into accepting an attacker’s login.
Passkeys can offer stronger phishing resistance because they are connected to the genuine website or application. However, users must still examine requests to share files, connect applications or change account permissions. Authentication protects the sign-in process; it does not make every message or action trustworthy.
If a manager, teacher, supplier or colleague asks for sensitive information unexpectedly, confirm the request separately. Call the person using a known number or begin a new message through an established contact. Do not use the contact details supplied in the suspicious communication.
The UK National Cyber Security Centre recommends contacting an organisation directly through trusted details when a message or caller appears suspicious. This simple pause helps prevent urgency and impersonation from controlling the decision.
Do not hide the mistake or wait to see what happens. Close the page and report the incident immediately to the organisation’s IT or security team. Explain what you clicked, whether you entered a password and whether you approved an MFA request or downloaded anything.
If login details were entered, change the affected password through the official service and sign out of unfamiliar sessions. Review account-recovery details, forwarding rules, connected applications and recent activity. The security team may also need to protect other accounts that use the same password.
Suspicious emails can be forwarded to the NCSC’s Suspicious Email Reporting Service. Prompt reporting can help investigators identify malicious websites and protect other users.
Regular awareness training, clear reporting procedures and supportive workplace responses make these cloud security best practices easier to follow. Users report incidents sooner when they know that fast action matters more than blame.

Check the complete website address before entering information. Misspellings, added words and unfamiliar domains may indicate a fake login page. Open the cloud service through its official application or a saved bookmark when you are uncertain.
Yes. Criminals may imitate an email address or use a compromised account belonging to a colleague, friend or supplier. Verify unexpected file-sharing, payment and password-reset requests through a separate trusted communication channel.
MFA blocks many attempts involving stolen passwords, but it cannot prevent every phishing attack. Never approve an unexpected authentication request or share a verification code. Passkeys can provide stronger protection against fake login websites where supported.
Report the incident immediately and change the password through the official service. Sign out of unfamiliar sessions and review connected applications, recovery details and email-forwarding rules. Contact your IT or security team for further support.
Yes. Reporting helps security teams warn other users and block malicious senders or websites. UK users can forward suspicious emails to the NCSC’s Suspicious Email Reporting Service.
Phishing and fake login pages succeed by creating trust, fear or urgency. Slowing down gives you time to examine the sender, website address and request before sharing sensitive information.
Safer sign-ins also require layered protection. Unique passwords, MFA, passkeys and regular account reviews reduce the damage an attacker can cause, but every unexpected approval request still needs careful checking.
Prompt reporting is equally important. If you click a suspicious link or enter account information, report the incident immediately so passwords, sessions and connected applications can be secured.
These actions are part of a wider approach to protecting cloud accounts and information. Read our cloud security best practices guide to learn how phishing prevention connects with secure file sharing, device protection, data privacy and incident response.
Phishing messages constantly change, but the principles used to assess them remain consistent. Cloud Security Awareness for Everyday Cloud Users helps learners recognise fake logins, suspicious links, malicious QR codes, unexpected MFA requests and other common cloud risks.