FormatFusionAll tools

Are online file converters safe? What the FBI warning actually means for you

By DJ, Founder of FormatFusion · 5 min read

There's a file you need to turn into another file, and a search result claiming it can be done for free. Before you upload your mortgage documents to a stranger's website, it's worth knowing that the FBI has something to say about this very situation.

The warning, and what it actually said

In March 2025, the FBI's Denver field office issued a public warning concerning free online file converter websites. In short: criminals set up sites that advertise free document conversion and use them to deliver malware, sometimes resulting in ransomware. In addition to the malware itself, any information contained in the uploaded documents can be stolen: Social Security numbers, banking details, passwords, and crypto wallet seed phrases.

Security researchers looked into the claim and discovered it was not merely hypothetical. Malwarebytes identified a list of suspicious converter domains using three methods: pushing a downloadable "conversion tool" that is in fact the malware, installing browser-hijacking extensions, and embedding malicious code into the file that comes back. BleepingComputer independently confirmed real fake-converter websites distributing detected malware, as well as paid search ads directing people to them. A spokesperson from the FBI pointed out how similar the fakes are to the genuine ones: scammers change "just one letter, or 'INC' instead of 'CO'" in the domain name.

The IT staff at MIT were more direct than anyone in an advisory to their own faculty: "Do NOT use them. Odds are more likely than not they are or have become malware delivery platforms."

What the warning did not say

Accuracy is important here. The FBI's warning concerns fake and malicious converter websites, mainly lookalikes and ad-funded fronts. It is not an accusation against the well-known converter brands you're familiar with. There has been no documented breach at the major companies, and their business model is subscriptions, not stealing your seed phrase.

What the established sites have in common is the upload method: your file goes to their servers, is processed there, and then remains on them for a period described in their policies:

These are actual policies from actual companies, and there is no basis for suspecting bad faith. Yet observe what they are: promises. As one commenter in a Hacker News discussion about converter sites pointed out, there is no way to verify the deletion actually takes place. That thread contains numerous security professionals noting an uncomfortable trend: offices regularly feed sensitive contracts, health records, and financial documents into converter sites, and corporate security training never mentions it.

So the honest view of the risk has two levels. Malicious converter sites can launch active attacks on you. Legitimate converter sites require you to extend trust, each time, that their copy of your file, however briefly it sits on their disks, is handled properly.

How to protect yourself

If you're going to use an upload-based converter, a few habits remove most of the danger:

  1. Type the address or use a bookmark. The recorded attacks lean on lookalike domains and search ads. Altering one letter is the whole scam.
  2. Never download a "converter app" from a converter website. The legitimate services carry out the conversion in the browser tab. A site that answers your upload attempt with "first install this tool" is describing malware.
  3. Scan what comes back. A converted file is still a downloaded file. Let your antivirus see it before you open it, in particular executables or anything that asks to enable macros.
  4. Match the file to the risk. A meme can go anywhere. A scan of your passport must never touch a server you don't control.

The option that skips the gamble

There is also a structural answer, and it's the reason FormatFusion was built. Modern browsers can run real conversion engines (FFmpeg, PDF renderers, image codecs) compiled to WebAssembly, directly on your own device. Since the conversion happens locally, the file never travels over the network at all. There is no upload to intercept, no server copy to breach, no deletion promise to take on faith, and no motivation to hand you a poisoned download.

That's how all 161 of our converters operate, from HEIC to JPG to PDF to Word. Open the page, and the browser carries out the task while your file stays in your hands. We've written before about why a converter shouldn't need your files, and the FBI warning is the strongest version of an argument we wish we didn't have: the safest upload is the one that never takes place.

The short version

Fake converter websites are a documented, FBI-confirmed malware channel, and they imitate the genuine ones down to a single letter. The legitimate upload-based converters are operated by real companies with published deletion policies, which still means your file spends time on another person's computer on the basis of a promise. For anything sensitive, use a converter that works locally in your browser, or desktop software you already trust. The best security advice in this entire story fits in one sentence: don't upload anything that didn't need to leave.

Files to convert while you're here?

Open the converter