A new phishing attack begins with a scam email disguised as an automated message from Microsoft SharePoint. The body of the email uses generic language to inform the recipient they have received a message containing important documents The email instructs the recipient to click on an embedded View Documents link. The link doesnt send the user to SharePoint as promised, however, it employs a series of redirects to send them to a landing page identical to a secure SharePoint file. This landing page displays the official Microsoft and SharePoint logos to convince the user they can trust the site.”]
Source: https://securityintelligence.com/news/sharepoint-phishing-attacks/