WatchOut #13 · Investigating
A cloud-storage address does not make a payment or sign-in page safe
Website Email Text message Messaging app Social media ImpersonationTechnology & workplace scams
Who may be targeted: Anyone who receives a link to a delivery, refund, prize, payment, sign-in, or download page hosted on an unfamiliar cloud-storage address.
What we are seeing
A link may show the name of a familiar cloud-storage company such as Amazon, Cloudflare, or Backblaze while displaying a fake delivery, refund, prize, or account page. The storage company may only be hosting the file; it does not mean the offer belongs to the company shown on the page. Do not enter passwords, card details, identity numbers, or verification codes. Open the real organization's app or website yourself instead.
Warning signs
- The address contains a familiar cloud provider's name but not the website of the organization shown on the page.
- The page uses a random bucket, file, or HTML filename instead of a normal organization web address.
- The page asks for card details, a CVV, a password, an identity number, or a verification code.
- An unexpected page says you must download a file or update before you can continue.
- The message creates urgency or promises a refund, prize, delivery, or account fix.
Source and limitations — what this alert does not establish
- Legitimate cloud-storage providers can be abused to host scam pages, but the provider name alone does not establish who created a file or how many people saw it.
Published Sep 8, 2026. Published by the Cybersecurity Reach Foundation.
Send this to someone it could protect.