Be alert to SharePoint phishing emails
We are currently seeing an increase in phishing emails that use Microsoft SharePoint file sharing notifications to trick colleagues and students into clicking malicious links.
2 June 2026
These emails appear to come from noreply@sharepointonline.com and typically state that someone has shared a file with you and you need to click a link to view it.
While SharePoint is a legitimate Microsoft service, attackers are actively abusing this trusted platform to make phishing emails appear genuine.
What these emails look like
Recent examples include emails that:
- Appear to come from noreply@sharepointonline.com
- State that a file has been shared with you and encourage you to click a link to view or access the file
- May include an external sender warning tag, despite appearing legitimate at first glance
In many cases, these emails are not related to any genuine activity and are designed to capture login details or personal information.
NUIT advice
This type of attack is particularly effective because it uses a trusted Microsoft service that many colleagues use day to day.
We strongly advise colleagues to be cautious of any unexpected SharePoint sharing notifications, especially where:
- You are not expecting a file to be shared with you
- The sender is unknown or external
- You are prompted to click a link or sign in to access content
If in doubt, do not click any links or open any attachments.
Reminder: 'too good to be true' scams
As we previously reported, alongside these SharePoint-based attacks, we continue to see phishing emails offering fake 'free' or high-value items, including previous campaigns referencing instruments, games consoles, and Apple products.
These messages usually appear to be sent from an internal address to encourage recipients to contact the sender via WhatsApp and pay a shipping fee. These are scams and should be treated as malicious.
As a rule, if something appears unexpected, unsolicited, or too good to be true, it is highly likely to be a phishing attempt.
What to do if you receive a suspicious email
If you receive a message like those described above:
- Do not click any links or open attachments
- Use the Report function in Microsoft Outlook to flag it as phishing (see below)
- If you have interacted with the email, contact the IT Service Desk immediately on 0191 208 5999
Once reported, no further action is needed unless advised by NUIT.
How to report phishing attempts
Use the dedicated report functions in Microsoft Outlook to help protect other users:
Classic Outlook

New Outlook

Microsoft Teams
1.Hover over the message
2. Click the three dots (… More options)
3. Select 'Report a concern' or 'Report message'
4. Submit the report
Stay vigilant
Phishing tactics continue to evolve, and attackers are increasingly using trusted platforms such as SharePoint to appear legitimate.
Please remain alert and always report anything unexpected or suspicious. Visit our spam and phishing guidance for more information and the latest advice on keeping your data safe.
Stay up to date with the latest University IT news by subscribing to the NUIT Newsletter – delivered straight to your inbox every two months.