Office of Information Technology
February 28, 2024
Tags Phishing Email (on campus)

Google Drive: Legitimate Notifications/Malicious Files

Phish Bowl Alerts

Be aware that Google Drive file share notifications are sent via "drive-shares-dm-noreply@google.com", but just because an email comes from this address, it doesn't automatically mean the content is legitimate or from within our organization. See below for a recent example. Yes, the message is sent via drive-shares-dm-noreply@google.com but the presence of grammatical errors in the sender name, a mix of unknown recipients outside our organization, and the topic of personal banking sent to your work email, are all red flags. While the notification is technically from Google Drive, the shared document is not from within Brown and is malicious. This is not an indication that your account or Google Drive has been compromised; rather, it's a common phishing tactic where attackers use legitimate services to distribute harmful content.

A screenshot of a phishing attempt masquerading as a Google Drive file notification.