Your company is participating in a Cyber Security Education Program.


This Sharefile Phishing Attack included the following social engineering techniques:


  1. Impersonation: The message claims to be from ShareFile to make the request appear legitimate.
  2. Urgency: “Signature Required” encourages the recipient to act quickly.
  3. Phishing link: Link inserted to make it easy to engage.
  4. Familiarity: Referring to “your company” makes the message feel like a routine workplace request.


How to spot this was a phishing email:


  1. Unexpected message?: Were you expecting a document that required your signature? If not, verify the request before clicking.
  2. Check the sender domain and link: the domain looks related to ShareFile, but it is not the expected ShareFile domain. (ex: reply-sharefile.com)
  3. Vague or missing details: The message does not identify the document, who sent it, or why your signature is required.
  4. Be cautious with requests to click: The email directs you to a link to view and sign the document rather than providing enough information to verify the request first.


“An employee is either an asset to your cyber security or a risk.”