Cybersecurity Reach Foundation
← All safety alerts
investigating

A cloud-storage address does not make a payment or sign-in page safe

A link may show the name of a familiar cloud-storage company such as Amazon, Cloudflare, or Backblaze while displaying a fake delivery, refund, prize, or account page. The storage company may only be hosting the file; it does not mean the offer belongs to the company shown on the page. Do not enter passwords, card details, identity numbers, or verification codes. Open the real organization's app or website yourself instead.

What to do

  • Stop if a cloud-storage link opens a page asking for a password, payment, identity number, verification code, or download.
  • Open the real organization's app or type its known website address yourself.
  • Check the full web address and confirm that it belongs to the organization you intended to visit.
  • Report the page to the impersonated organization and the hosting provider, then delete the message or advertisement.
  • Contact your bank or change exposed passwords through the official service if you already submitted information.

What this alert does not establish

  • Legitimate cloud-storage providers can be abused to host scam pages, but the provider name alone does not establish who created a file or how many people saw it.

Share this warning

This alert is also on WatchOut, our shareable alert feed, with one-tap sharing and free email alerts.

Last updated:

This alert is maintained from the shared Cybersecurity Reach Foundation / ScamArchive alert record.