
By Michael Canfield
IT Communication Specialist
Published September 28, 2026
An email says someone has shared a document with you. It looks familiar, with a notification from Google, Box, or Microsoft. It may even have been sent from someone you know and trust. But you weren’t expecting a file. What should you do? Pause, and take a moment before opening it.
Attackers can use file-sharing services and fake urls to send convincing messages from compromised accounts. That means even a notification sent through a legitimate service may be part of a scam or phishing attempt.
“These messages can take advantage of the trust people place in familiar collaboration tools,” said Dr. Catherine J. Ullman, Principal Technology Architect, Security.
File-sharing notifications are a routine part of working and learning at UB. That familiarity can make an unexpected invitation easy to overlook.
Ullman described examples involving Google and Box, as well as similar messages involving Microsoft services. The concern is that an attacker may control the account sharing the file and use the invitation to draw someone into an interaction that puts their information at risk.
“They use these to compromise accounts and get access to other things,” Ullman said.
The key question is whether the shared file makes sense: Were you expecting it? Do you recognize the person sharing it? Is it connected to something you’re working on?
Before acting on an unexpected file-sharing notification:
The UBIT Help Center is here to help with your technology needs at UB. Students can also reach out to the UB Tech Squad for help; they can meet you anywhere on North or South Campus.
UB Information Technology News keeps UB students, faculty, and staff informed about their IT services and showcases creative collaborations between UBIT and the campus community. Published by UB Information Technology and distributed via email as The Monthly Download. Edited by Diana Tuorto, IT Communication and Engagement, dianatuo@buffalo.edu.