Are Online Converters Safe? FBI Warning
The FBI warned some free converters spread malware. How the scam works, red flags to watch for, and why client-side tools are safer.
By Formatly
Free online file converters are some of the most-used tools on the internet — and in March 2025, the FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement warning that cybercriminals were operating fake file-converter websites to distribute malware. If you’ve ever Googled “convert X to Y free,” this affects you directly. Here’s what the warning said, how the scam works, and how to protect yourself.
What the FBI warned about
The IC3 announcement (PSA-250313) described a straightforward scheme: criminals build websites that claim to convert files — documents, images, audio — for free. The “converted” file the victim downloads is bundled with malware, or the site itself uses the conversion process as cover to compromise the visitor’s machine. The FBI’s advice boiled down to: verify the site is legitimate, keep security software current, and be deeply suspicious of free converters you’ve never heard of.
This wasn’t theoretical. Security researchers had been documenting malicious converter sites for years — the FBI warning was the moment it became official guidance.
How malicious converters work
The fake download. You upload your file, the site shows a convincing progress bar, and the “converted” download is an executable (or a ZIP containing one) disguised with a familiar icon. document.pdf.exe with Windows hiding extensions is the classic.
The “required” software. The site claims your file needs a special codec, viewer, or “download manager” to convert. That download is the payload.
Drive-by compromise. The shadiest sites don’t even need you to download anything — malicious ads or exploit kits on the page itself target unpatched browsers.
Data harvesting. Even “legitimate-looking” converters can be data collection operations: your uploaded files — ID photos, contracts, unreleased work, personal photos — sit on someone’s server, subject to whatever their actual (not advertised) data practices are.
Red flags
- Aggressive popups and fake “Download” buttons — legitimate tools don’t need five download buttons, four of which are ads
- Asking you to install software to convert a file — real converters work in the page
- No company identity — no about page, no contact, no privacy policy, domain registered last month
- HTTP instead of HTTPS in 2026 is an instant disqualification
- The converted file has an unexpected extension (
.exe,.zipwhen you expected.pdf) — never open it - VirusTotal flags — paste any suspicious URL into virustotal.com before uploading anything
Why client-side converters are structurally safer
Here’s the key distinction the FBI warning implies but doesn’t spell out: a converter that processes files in your browser never receives your files at all.
With a traditional converter, your file travels to a server, gets processed who-knows-where, and a result comes back. You are trusting their infrastructure, their code, their employees, and their honesty — a privacy policy, which is just a promise.
With a client-side tool (like every tool on Formatly), the conversion code downloads to your browser once, and your file never leaves your device. There is no server holding your photos. There is nowhere for your files to leak from. The privacy guarantee is architectural — it’s true because of how the system is built, not because someone promised to behave.
This doesn’t make client-side tools magically immune to everything (a compromised site could still serve bad JavaScript — which is why open, reputable tools matter), but it eliminates entire categories of risk: no uploads to intercept, no server-side file retention, no “we delete after 1 hour” promises to trust.
Practical safety checklist
- Prefer client-side tools — if the site says files never leave your device (and its architecture backs that up — no upload progress bar for “sending”), that’s the safest category
- Check the domain’s reputation — established sites with real about pages and contact info
- Never run downloaded “converter software” — conversion happens in the browser or it doesn’t happen
- Scan unexpected downloads — if a converted file arrives as
.exeor an unexpected archive, delete it and scan - Keep your browser updated — drive-by attacks target old browsers
- For sensitive files (IDs, medical, legal, unreleased work) — client-side only, no exceptions
The bottom line
The FBI warning wasn’t “never convert files online.” It was “the free converter you found on page 3 of Google might be a trap.” Stick to reputable tools, prefer ones that process files locally in your browser, and treat any converter that asks you to install something as hostile.
Practical next steps
- Every Formatly tool runs 100% in your browser — your files never leave your device, by architecture, not by promise.
- Converting photos? Strip EXIF metadata too — location data in photos is its own privacy risk.
- Learn what EXIF data reveals about you before your next upload.