We see millions of phishing emails every day, but one recently stood out: a sophisticated scam targeting Google Docs and Google Drive users' login credentials. The scam was recently discovered by Symantec.
The scam comes via email, has a simple subject line of “Documents,” and invites the recipient to view an important document on Google Docs by clicking on the included link.
Of course, the link doesn’t go to Google Docs, but it supposedly takes you to Google, presenting a very convincing fake Google Docs login page:

The fake page is hosted on Google servers and served over SSL, making the page even more convincing. The scammers have simply created a public folder within a Google Drive account, uploaded a file, used Google Drive's preview feature, and obtained a publicly accessible URL that they include in their messages.
This login page will look familiar to many Google users, as it is now used across all Google services. It states which service it grants access to, but this is a subtlety that many will not notice.
If someone clicks “Login”, the user's credentials are sent to a PHP script located on a hacked web server.
This page then redirects to a real Google Docs document, making the whole attack very convincing. Google accounts are a valuable target for phishers, since they can use them to access many services.

