The message does not come from a stranger. It comes from the superintendent, or from HR, or from the business office, and it asks for something those offices ask for all the time: confirm your direct deposit details, review your evaluation, approve this payment, open the document I shared with you.
None of those people sent it. This guide is about why their names are the ones borrowed, how the messages get in, and what a district's IT office can do about a problem that is only partly technical.
The short answer
Attackers impersonate the roles that can legitimately ask staff for money, credentials or urgency. In a district those roles are the superintendent, principals, HR, payroll and the business office. The request looks routine because, coming from those offices, it would be.
The lure can arrive as ordinary spoofed email, from a lookalike domain, from a free account wearing a real name, from a compromised account at another school, or as a genuine Google Drive share notification. The last two pass every technical check, because nothing about them is forged.
These attacks depend on recipients noticing a familiar name before they scrutinize the address. Most recipients read the name and the request. Fewer read the address, and fewer still read the account that shared a Drive file.
District IT can raise the cost with authentication controls on its own domain, Gmail's spoofing protections, Drive's external-file warnings and receiving controls, a reporting path people use, and a compromised-account response that is ready before it is needed. None of that replaces the sentence staff need to hear.
Why these roles
Authority. A request from the superintendent's office is acted on before it is questioned. That is what the office is for, and attackers use it.
Urgency that sounds normal. Before payroll closes, by end of day, before the board meeting: deadlines are how these offices actually communicate, so a manufactured one does not stand out.
Routine money flows. Payroll changes, direct-deposit updates, benefits enrollment, vendor payments and reimbursements are ordinary transactions that these roles initiate or approve. A lure that imitates one asks for nothing unusual.
Documents are how the work moves. Evaluations, contracts, schedules and handbooks arrive as shared documents. A shared document with an HR title is not a strange object in a teacher's inbox.
Public information makes the impersonation accurate. Names, titles, photographs, meeting calendars and email addresses are on the district website. EdTech Magazine reported attackers "impersonating superintendents and principals using real details lifted from district websites and public communications", with messages that "can reference a real meeting or deadline to create urgency while attaching a malicious document."
The lures, as reported
These are the themes that appear in published examples. Nothing here says which is most common; no such measurement exists in the public record.
- Payroll and direct deposit. A request to confirm or update banking details, often "before the next pay date."
- Benefits and HR documents. Open enrollment, a policy update, a form that needs a signature.
- Staff evaluations. Penn State's security office published an example years ago in which the shared file was simply named Evaluation.pdf and the notification named a university leader as the sharer.
- Payment and invoice requests. A vendor payment or a gift-card purchase that "the superintendent" needs handled quietly.
- Contact-information verification. The Oklahoma State Department of Education warned districts of a message asking superintendents and districts to "verify or update their contact information", which the department said it did not send.
- Shared documents. Any of the above delivered as a Google Drive share, so that the email is generated by Google and the lure is inside the document.
How they get in
Plain spoofing of your domain. A message with a From address at your domain that your domain did not send. This is the variant the authentication standards were built for: with SPF and DKIM configured and a DMARC policy of reject, receiving servers that honor DMARC are instructed to reject mail that fails DMARC alignment.
Lookalike domains. A domain one character off from yours, or the same name at a different top-level domain. Gmail has a setting for this, Protect against domain spoofing based on similar domain names, which Google describes as protecting "against incoming messages from domains that appear visually similar to your company's domains or domain aliases."
A free account wearing a real name. The display name says Dr. Dana Whitaker, Superintendent; the address is at a free-mail provider. Gmail's Protect against spoofing of employee names is aimed at exactly this: "messages where the sender's name is a name in your Google Workspace directory, but the email isn't from your company domain or domain aliases."
A compromised account at another school. The message comes from a real account at a real district, authenticates correctly, and carries a familiar-looking domain. Nothing is forged. Published examples of Drive-share phishing frequently trace back to accounts like this.
A Google Drive share notification. The attacker shares a document from a Google account and Google sends the notification. Google's own administrator help describes the result: the links "can also appear in Drive's automatic email notifications. Because the email notifications come from Google, users might be tricked into thinking message contents are legitimate." The mail sender is Google, the sharer is the attacker, and the name on the document is your colleague: three identities, taken apart in Google Drive share phishing: why the email is real and the document is malicious.
The first three are sender and domain impersonation techniques, and the technical controls below reach them. The last two are not, and the controls that reach them are about receiving and about people.
Why the name wins
A recipient has a fraction of a second and two pieces of information: a name they recognize and a request that fits the name. The address is a third piece, in smaller type, that most mail clients de-emphasize and that mobile clients often hide. On a Drive notification the account that shared the file is a fourth piece, further down, in the body.
Attackers know which piece people read. Training that tells staff to "check the sender" is asking them to change reading order under time pressure, which is why it works less well than a rule that removes the need: these offices never ask for this by email or by unsolicited share. When the request itself is the tell, the name stops mattering.
What district IT can do
Authenticate your own domain. SPF, DKIM and DMARC protect your domain name from being used in the first variant. Google's description of DMARC is the whole idea in one sentence: it "tells receiving email servers what action to take on messages sent from your domain that don't pass SPF or DKIM authentication." Set SPF and DKIM first, then a DMARC policy, and understand what it does not cover: a message Google sends about a Drive share authenticates as Google's, correctly. The limits are the subject of why SPF, DKIM and DMARC don't stop Google Drive share phishing.
Turn on Gmail's spoofing protections. The employee-name, lookalike-domain and unauthenticated-mail settings are available on Education Fundamentals, Standard and Plus, each with the choice of warning, spam or quarantine. Google's Protect against inbound emails spoofing your domain is described as protection "against potential Business Email Compromise (BEC) messages not authenticated with either SPF or DKIM, pretending to be from your domain." Turn them on; then remember that a Drive notification is not spoofed, and Google does not document whether the employee-name check applies to its own notification mail.
Keep the External badge on. Docs, Sheets and Slides files owned by or shared with an outside account carry an External badge with a report option, controlled under Drive sharing settings as Highlight external files and on by default. It is the one indicator that sits on the document rather than the email.
Decide who can receive external shares. Google's own recommendation for Drive spam and phishing is an allowlist with receiving from outside it turned off, or, on Education Standard and Plus, trust rules with a Receiving files trigger. The trade-offs, and a K-12 approach that tightens receiving for students and the business office while leaving teachers open, are in how to reduce Google Drive share phishing.
Enforce 2-Step Verification on staff. It does not stop a lure from arriving. It makes a stolen password alone insufficient in many attacks, and a compromised account in your district is the sender of the next district's incident. For administrators and other high-value accounts, use security keys: Google calls them "the most secure form of 2SV" and says they "protect against phishing threats."
Publish one reporting path and make it painless. Report phishing in Gmail, Block or report in Drive, and one address or button for "I'm not sure." Every report gives you a starting point for scoping the campaign.
Have the compromised-account response written down. When someone enters a password, the sequence is suspend, then reset, then hunt for filters, forwarding, delegation, app passwords and connected applications, then check the sign-in history for when it really started. It is in what to check after a Google Workspace account is compromised, and it is a poor thing to design at four in the afternoon.
Adopt one policy that removes the ambiguity. Leadership, HR and the business office never request banking changes, credentials or payments by email, and never distribute pay, HR or evaluation documents by unsolicited Drive share. Announce it. Then a message that does any of those things is wrong on its face, whoever it appears to be from.
K-12 specifics
The org chart is public. Superintendent, assistant superintendents, principals, business manager, HR director, with photographs and emails, on the district site. That is the impersonation kit.
Payroll runs on a calendar everyone knows. Pay dates, contract renewals, evaluation windows and open enrollment are published, and lures arrive to match them. That is a pattern from published examples; how often it happens in any one district is not measured.
Peer districts are trusted senders. A compromised account at a neighboring district looks legitimate to your staff and, if you have allowlisted that district in Drive, to your configuration as well.
Staff turnover resets training. New hires, substitutes and seasonal staff have not heard the one sentence yet, and they are the ones who most want to do what the superintendent's office asks.
Students are targets too, differently. Student accounts receive the same Drive shares and rarely have a legitimate reason to receive one from an arbitrary outside account, which is why receiving restrictions cost the least there.
What not to do
Do not assume "it came from Google" or "it passed DMARC" means safe. Both statements can be true of a message whose document is a credential harvester.
Do not reset the impersonated person's password as a reflex. They were named, not compromised, unless the sending or sharing account is theirs.
Do not block Google's Drive notification address. You lose every legitimate share and keep the malicious document (why).
Do not assume one report means one recipient. Scope the campaign before deciding how far it spread; the reporter is the one who noticed.
Do not build training on "look for bad grammar." Modern lures can be polished and convincing.
Sources
- Advanced phishing and malware protection — Google Workspace Admin Help. The employee-name, lookalike-domain, unauthenticated-mail and domain-spoofing (BEC) settings quoted above.
- Set up DMARC — Google Workspace Admin Help. The definition of DMARC.
- Help prevent Drive spam and phishing — Google Workspace Admin Help. Why notifications from Google mislead users, and the allowlist and trust-rule measures.
- Manage external sharing for your organization — Google Workspace Admin Help. The Highlight external files indicator.
- Enhance Your Organization's Security with Out-of-Domain File Warnings — Google Workspace Updates. The External badge and its report option.
- Deploy 2-Step Verification — Google Workspace Admin Help.
- Protect your business with 2-Step Verification — Google Workspace Admin Help. "Security keys are the most secure form of 2SV and protect against phishing threats."
- AI-Driven Phishing Is Putting K–12 Schools at Risk — EdTech Magazine. Reported impersonation of superintendents and principals using details from district websites.
- OSDE warns of phishing email targeting schools, superintendents — KFOR, via Yahoo News. A state education department's warning about a contact-verification lure aimed at superintendents.
- Google Drive: Legitimate Notifications/Malicious Files — Brown University OIT. A published example of a genuine Drive notification carrying a malicious file.
- Evaluation.pdf (via Google Drive) — Penn State Information Security. A published example using a staff-evaluation lure.
Related field guides
- Google Drive share phishing: why the email is real and the document is malicious
- How to reduce Google Drive share phishing in Google Workspace
- Why SPF, DKIM and DMARC don't stop Google Drive share phishing
- What to check after a Google Workspace account is compromised
Impersonation is a people problem with a technical edge, and the edge is where tooling belongs: pulling a lure out of every inbox it reached after someone reviews the list, and running the containment steps in order on any account that entered a password. That is what Message Removal and the security tools in ORINEX Workspace Compliance are for. What ORINEX Workspace does.