Threats Vulnerabilities

WeTransfer Phishing Attack: How Trusted Links Steal Credentials

Written by Shweta Shelke | Sep 21, 2026, 10:00:55 AM

Quick Answer

Attackers are abusing legitimate WeTransfer links to make phishing emails appear trustworthy. In this WeTransfer phishing campaign, users were directed to a real WeTransfer page, prompted to download an HTML file, and then redirected to a fake login page designed to capture Microsoft 365 and corporate credentials. Organizations should validate whether WeTransfer is required for business use, block identified malicious senders and domains, monitor related phishing activity, and remind users to report suspicious messages in Outlook.

ProArch SOC investigated a phishing campaign in which attackers abused the legitimate file-sharing service WeTransfer to deliver credential-harvesting content. The email used a trusted WeTransfer link that redirected users to a real WeTransfer page, increasing the message’s credibility. After interacting with the file-sharing page, users downloaded an HTML file that redirected them to a fake login site designed to steal credentials.

What is happening in WeTransfer Credential Harvesting Attacks?

Attack chain observed

  • A phishing email was sent from a legitimate WeTransfer domain, which made the message appear more trustworthy.
  • The email contained a WeTransfer file-sharing link.
  • The link took users to a real WeTransfer page, which reduced suspicion before the malicious download.
  • User interaction resulted in the download of an HTML file.
  • When opened, the HTML file redirected the user to a credential-harvesting website.
  • The phishing site attempted to collect user credentials through a fake login page.

Risk / Why It Matters

Who is at risk: Any user who receives file-sharing emails from external senders, especially messages that prompt them to download HTML files or sign in after opening a shared file, may be exposed to this type of credential-harvesting attack.

  • Credential Theft
    Attackers can steal Microsoft 365 and other corporate credentials entered into phishing pages.
  • Account Compromise
    Stolen credentials may allow unauthorized access to corporate email, cloud applications, and internal resources.
  • Business Email Compromise (BEC)
    Compromised accounts may be used to conduct internal phishing attacks, financial fraud, or further malicious activity.
  • Data Exposure
    Unauthorized access to business systems may result in the exposure of sensitive corporate information.
  • Operational and Reputational Impact
    Successful credential theft can disrupt business operations, increase incident response costs, and damage organizational trust.

How Did ProArch SOC Respond to the WeTransfer Phishing Attack?

After investigating the phishing activity, ProArch SOC took the following containment and remediation actions

  1. Reset the affected user’s password and revoked all active sessions.
  2. Deleted the identified phishing emails.
  3. Blocked the sender.
  4. Blocked the identified phishing and redirecting domains.
  5. Added the malicious HTML file hash to IOC.
  6. Stopped and quarantined the downloaded file.
  7. Reviewed the device timeline for additional suspicious activity.
  8. Initiated a full antivirus scan on the affected device.

What Are the Warning Signs of a Fake WeTransfer Email?

Unexpected WeTransfer notifications, unfamiliar senders, files that download as HTML,login prompts after opening a shared file, and messages that create urgency around downloading or viewing content.

  • Confirm whether WeTransfer emails are required for legitimate business communications.
  • If WeTransfer-related emails are not required, block the sender/sender domain in the Microsoft Defender for Office 365 (MDO) Tenant Block List to prevent similar emails from being delivered in the future.
  • Monitor for phishing attempts related to this campaign.
  • Please remain vigilant when receiving emails from external senders or unfamiliar domains, especially before
    • Opening attachments
    • Clicking embedded links
    • Downloading files
    • Providing credentials

If you receive a suspicious email, report it immediately using the “Report Message” button within Outlook. This allows the Security Team to quickly investigate and classify emails as Spam or Phishing, helping protect other users from similar threats.