How the Scam Works:
You receive an email notice that someone shared a Google Doc with you, and you can access it by clicking on a link. If you click through, you are taken to an exact copy of the Google log-in page.
The look-alike log-in form prompts you to enter your Google username and password. The data is sent to the scammer's server, but you are redirected to a real Google Doc. This means you are probably unaware anything even happened!
The scammers are using an actual Google Drive account to host the scam file, which lends a legitimizing Google.com URL to their con. Inputting your email and password into the fake form gives scammers access to your Google Drive, Gmail and any personal information stored within.
Tips for protecting your Google account:
If your account may have been compromised.... Be sure to review this security checklist to make sure scammers aren't accessing your email. Topics covered include checking past log-in locations and making sure auto-forwarding isn't activated.