Security advisory: Watch for fake SharePoint and OneDrive file-share phishing emails

Security Advisory

An active phishing campaign is sending fake SharePoint and OneDrive "someone has shared a file with you" notifications to District employees. The email arrives from a real Microsoft address, so it passes spam filtering, but the shared document contains a link that steals your Solano password.

Action required: Use the checklist below before opening any shared file. Do not enter your password or approve a multifactor authentication prompt after opening a shared document. Report suspicious file-share emails to the Technology Services Help Desk.

Advisory details
Article type Security Advisory
Audience All employees
Severity High
Status Active
Last updated June 29, 2026

Summary

Attackers are sending fake "someone has shared a file with you" notifications through the real SharePoint and OneDrive sharing service. Because the email is generated by Microsoft, it passes spam filtering and looks legitimate. When you open the shared document, it contains a link to a fake sign-in page that captures your Solano password and multifactor authentication response.

The same campaign has been observed at other California Community College districts.

Who is affected?

All District employees who use Microsoft 365 email are potential targets, including full-time and part-time faculty, classified staff, administrators, and student employees.

If you are not a District employee, no action is required unless otherwise stated below.

What this scam looks like

Examples observed in this campaign:

Observed phishing message details
Sender address no-reply@sharepointonline.com
Example subject [First name last name] shared "Solano Community College Staff File Attachement Notice" with you
Document titles seen Staff File Attachement Notice, Staff Benefit Notice, Staff Appointment Notice, Document 1.docx

The sender address is a real Microsoft SharePoint notification address, so the presence of "sharepointonline.com" alone does not confirm the message is safe. Judge the message by who is sharing, whether you expected the file, and what happens after you open it.

Before you open a shared file, check

  • Were you expecting it? An unexpected share, especially from someone you do not work with, is the top warning sign.
  • Is the sharer external? Look for an outside or personal address, such as a Gmail or Yahoo address, or a name you do not recognize.
  • Odd title or wording? Generic titles such as "Staff Notice," "Staff Benefit," or "Staff Attachment," a sense of urgency, or misspellings, such as "Attachement" or "Set you a file," are common in these messages.
  • Does it ask you to sign in again? Being re-prompted for your password or a multifactor authentication approval after opening a document is a red flag. A legitimate share inside Microsoft 365 will not ask you to sign in again on a separate page.

If you think it is malicious

  1. Do not click the link inside the shared document, enter your password, or approve any multifactor authentication prompt.
  2. Report it by submitting an Information Security Incident.
  3. After you report it, delete the email from your inbox and from Deleted Items.

If you already clicked the link or signed in

Act quickly. The attacker may be able to sign in as you within minutes.

  1. Contact the Technology Services Help Desk right away at (707) 864-7000 extension 4690 or submit an Information Security Incident.
  2. Do not delete the suspicious email, the shared file notification, or any inbox rules. Technology Services needs them for the investigation.
  3. Change your Solano password from a known-good device only after Technology Services confirms it is safe to do so.

Protect sensitive information: Do not include passwords, verification codes, recovery codes, tokens, or other secrets in a service request or email to the Help Desk.