Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI warning is about malicious free online document-converter websites—not a newly discovered flaw in Chrome, Edge, or Safari. Criminals use ordinary browsing and look-alike sites to trick people into downloading malware, installing unwanted extensions, or opening a dangerous converted file.

What the FBI warning is about

In March 2025, the FBI’s Denver field office warned that criminals were using free online document converters to deliver malware. The warning applies to anyone who visits a deceptive site, regardless of browser. It does not establish that Chrome, Edge, or Safari has a shared vulnerability.

Scammers may advertise familiar tasks such as converting DOC to PDF or PDF to DOC. A site can then prompt you to download a file, install a browser extension, or retrieve a converted document containing malicious code. Possible consequences reported include credential theft, identity theft, and ransomware. Forbes’ March 18, 2025 report describes the warning and reproduces reporting from Malwarebytes on these tactics.

The scale of online document-site abuse is a reason for caution, not a count of victims of this particular scam: Cofense reported that online document websites represented 8.8% of credential-phishing campaigns in 2024, a figure reproduced in Forbes’ March 27, 2025 report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

How to spot a risky converter site

  • Check the domain carefully. Look for misspellings, extra words, or a domain that imitates a familiar company. A padlock or HTTPS alone does not prove a site is legitimate.
  • Be wary of search ads. An advertisement can lead to a look-alike site; verify the destination before entering information or uploading a document.
  • Reject unexpected installs. A basic conversion request should not prompt you to install an unfamiliar executable or browser extension. Close the page rather than following the prompt.
  • Handle the result as untrusted. A file presented as the converted document can still be dangerous. Scan it before opening, and do not enable macros or other active content just because the site says they are required.
  • Consider privacy as well as malware. Uploading a document gives the service access to its contents. Avoid unknown sites for sensitive, personal, or business documents.

Safer ways to convert a document

For occasional conversions, prefer a trusted application already installed on your device or an established service whose address you enter yourself or reach through a saved bookmark. No online converter should be assumed safe solely because it appears in search results or offers a free conversion.

When comparing options, check whether conversion happens on your device or requires uploading the file; who operates the service and what it says about privacy and file retention; whether it requires an extension or executable; what formats it supports; and whether it explains how files are scanned. These checks help assess risk but cannot guarantee that a service or file is safe.

What to do if you used a suspicious converter

If you only visited the site

Close the page and do not download or install anything from it. Keep your operating system and security software updated. If the site triggered a download, do not open the file; use your security software to scan it and remove it if flagged.

If you downloaded a file or installed an extension

  1. Do not open the downloaded file. Run a security scan with updated security software and follow its instructions to quarantine or remove detected threats.
  2. If you installed an unfamiliar extension, remove it using your browser’s extension settings. If you cannot remove it or the device behaves unexpectedly, disconnect it from the network while you seek trusted technical help.
  3. If a scan finds malware or you suspect the device is compromised, use a clean device for account recovery. Change affected passwords and enable multifactor authentication where available.

If you entered a password or payment details

From a device you trust, change the affected password and any reused passwords, then enable multifactor authentication. Contact the relevant bank or service provider promptly if you shared financial information or see unauthorized activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Report suspected fraud

Preserve the website address, downloaded files, messages, and any transaction details. The FBI advises reporting suspected fraud to the Internet Crime Complaint Center (IC3). Its guidance also recommends checking destination URLs, typing a known business address directly or using a bookmark, being cautious with search ads, considering an ad-blocking extension, and keeping security software current: FBI guidance published April 24, 2025.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the warning does not establish

The FBI guidance does not provide a definitive list of malicious converter domains or a count of affected users, and it does not say that Chrome, Edge, or Safari themselves are vulnerable. Scam domains and payloads can change, so a domain mentioned in a report should not be treated as a permanent blacklist. The FBI’s message, quoted in Forbes’ March 18 report, is that “The best way to thwart these fraudsters is to educate people so they don’t fall victim to these fraudsters in the first place.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.