File-sharing platforms like WeTransfer, Dropbox, Google Drive, and OneDrive are convenient and trusted, which is exactly why scammers target them. Criminals send fake file-sharing notifications to trick you into revealing passwords, downloading malware, or opening dangerous documents.
๐ How the WeTransfer Scam Works
๐ฉ Fake file-share notifications claiming to be from colleagues, clients, or companies.
โณ Urgent messages like โReview this ASAPโ to pressure quick clicks.
๐ญ Links to counterfeit WeTransfer login pages to steal credentials.
๐ป Malware hidden in the โshared fileโ download.
๐ Real-world case: In 2019, a WeTransfer breach accidentally sent files to the wrong recipients showing vulnerabilities scammers can exploit.
๐ Similar Scams on Other Platforms
๐ฆ Dropbox
โ๏ธ Phishing emails using fake Dropbox branding (โno-reply@dropbox-mailโขcomโ) leading to credential theft or malware.
๐ Stolen logins from past breaches used to send malicious files.
๐ข Fake HR messages about โbenefitsโ or โpayroll changesโ carrying malicious links.
๐ Google Drive
๐ง Bogus Google Doc notifications (โProject Proposal 2025โ) leading to fake login pages.
๐ฆ Malware embedded in Google Docs or shared Drive files, bypassing email filters.
โก Urgent โAccount lockedโ warnings to trigger impulsive clicks.
โ๏ธ OneDrive
๐ โRestricted fileโ tricks requiring sign-in on fake Microsoft pages.
๐ผ Business email compromise โ hacked contacts share malicious files via legitimate OneDrive alerts.
๐ฉ Fake IT emails claiming to be โOneDrive Security Updates.โ
๐ฉ Red Flags
๐ซ Unexpected file-sharing requests from unknown or off-domain senders.
โฐ Threats like โAct now or lose access!โ
๐ Links with look-alike domains (e.g., drive-login-secureโขcom).
โ๏ธ Typos, bad grammar, or low-quality branding.
๐ Requests for passwords, payments, or โstorage upgrades.โ
๐ก How to Stay Safe
๐ Verify the senderโs email address โ hover over links before clicking.
๐ Go directly to the platformโs official website or app, never via email links.
๐ Enable two-factor authentication on all file-sharing accounts.
๐ Scan all downloads with reputable antivirus software.
๐ Slow down if a message feels rushed or threatening.
๐ค Report phishing emails to the platform and your email provider.
๐ If You are Targeted or Compromised
๐ท Do not click or download anything suspicious.
๐ If you entered credentials, change your password immediately on a safe device.
๐ง Check for unauthorized account activity.
๐ข Report to the platformโs support team and relevant cybercrime authorities (e.g., FTC, CISA).
๐ก Tip: For highly sensitive files, use services with true end-to-end encryption. WeTransfer, Dropbox, Google Drive, and OneDrive do not enable this by default.
- Log in to post comments