Free PDF editors, file converters and malware-analysis services can create an unexpected data-leakage problem for businesses when employees use them without understanding where their data goes.
For many organisations, cybersecurity discussions focus on phishing, ransomware, credential theft and malicious attachments. But there is another, much quieter risk that can sit outside an organisation’s traditional security controls: employees uploading company information to free online utility services to perform their work related duties.
These services are often convenient and, in many cases, genuinely useful. They can merge or split PDFs, convert documents between formats, compress files or perform other tasks that employees may not have the software or licences to perform locally.
The problem is that “free” does not necessarily mean “risk-free” but more “risk-plentiful”.
Free file conversion can mean sending corporate data elsewhere
Consider the common scenario of an employee needing to convert a document from one format to another.
Rather than installing approved software, the employee queries google or chatgpt for an online conversion service, uploads the document and downloads the converted version. Ive seen an employee upload a large payroll file to chatgpt and ask it to split it into smaller files and when chatgpt said it could not, the employee then asked for online sites which could do the task and then proceeded to upload the payroll file to each of the sites chatgpt listed.
From the user’s perspective, the process can appear harmless. From a security perspective, however, the organisation has just transferred a potentially sensitive file to a third-party service.
One example encountered during testing was FreeConvert[.]com.
Its published documentation and terms provide information about how uploaded files and user data are handled. However, determining precisely where data is processed and stored can be more complicated than a user might expect.
In my testing, a file upload and subsequent download involved infrastructure associated with multiple providers and geographic locations, none of which matched those documented in the sites terms. This highlights an important issue for security teams: an organisation may believe it understands where its data is being processed based solely on a service’s published privacy documentation, while the underlying delivery and hosting infrastructure can be more complicated.
That does not, by itself, demonstrate malicious activity or a security vulnerability in the service. It does demonstrate why organisations should understand the complete data flow before allowing employees to upload business information to third-party websites.
The PDF problem
PDF editing services present another common example.
Services offering free or freemium PDF manipulation capabilities can be extremely attractive to employees who need to make a quick change to a document but do not have access to licensed desktop software.
I have encountered employees across a range of departments—including HR and payroll—using online PDF tools to perform routine business tasks.
The security concern becomes obvious when you consider the types of documents these departments routinely handle.
A PDF uploaded for editing might contain:
- Employee personal information
- Payroll information
- Employment contracts
- Tax documentation
- Customer information
- Financial records
- Internal correspondence
- Confidential business information
The employee may have no malicious intent whatsoever. They may simply be trying to complete their job.
But from an information-security perspective, the organisation has potentially handed sensitive information to a third party without the appropriate contractual, privacy or security review.
“We needed the tool” isn’t a security control
There is an important distinction here.
The problem is not necessarily that online PDF editors or file converters are inherently malicious.
The problem is unsanctioned data transfer, shadow IT and the lack of security awareness by the employee.
If an organisation has approved a particular service, completed the necessary security and privacy assessments, established appropriate contractual protections and configured its controls appropriately, the risk may be manageable.
The situation is very different when an employee discovers a free service through a search engine and begins uploading corporate documents to it.
This is a classic example of shadow IT.
The employee may even be attempting to follow company policy by finding a way to complete their work without installing unauthorised software. Unfortunately, the workaround can create a much larger security or privacy problem that the employee is completely unaware of.
Even security tools can expose sensitive information
The same issue extends beyond file conversion.
Security professionals and technically minded employees increasingly have access to online malware-analysis and sandboxing platforms. These services can be extremely valuable when investigating suspicious files, URLs and malware.
However, users need to understand the visibility associated with the service and account tier they are using.
Many free or community-oriented malware-analysis platforms make submitted samples or analysis information publicly accessible. This is not done by deceit as the platforms will readily advertise they are doing this although users rarely take the time to read and understand all the text on a website.
That creates a potentially serious problem if an employee uploads the wrong file.
A sample submitted for analysis might inadvertently contain:
- A business document
- A customer file
- A contract
- A personal email
- Internal URLs
- Credentials or tokens
- Proprietary software
- Other sensitive information
The intention may be entirely defensive: an employee is trying to determine whether something is malicious.
The result could nevertheless be an unintended disclosure.
Threat actors are watching too
There is another consideration for organisations using public malware-analysis services.
Threat actors themselves happily pay for a subscription and use these platforms. A paid subscription usually allows them access to the APIs and the ability to query all the free submissions.
That is not particularly surprising. Malware researchers, incident responders and attackers all have an interest in analysing malicious files and URLs.
Publicly visible submissions can therefore provide valuable intelligence about what security researchers, victims and other threat actors are investigating.
This makes it particularly important for organisations to understand the visibility and retention policies of any analysis platform before submitting potentially sensitive material.
The question should not simply be:
“Can this website analyse the file?”
It should also be:
“Can anyone else can see the file, its metadata or the resulting analysis?”
Security teams should look for the behaviour, not just the domains
Organisations do not necessarily need to start by blocking every website containing the word “PDF” or “free”.
Instead, security teams should try to understand what employees are actually using.
Depending on the organisation’s security tooling, useful sources of information may include:
- DNS logs
- Secure web gateways
- Proxy logs
- Firewall telemetry
- Browser or endpoint telemetry
- CASB/SSE platforms
- Cloud access monitoring
- Data-loss prevention controls
Searching for commonly used online file-conversion, PDF-editing and sandboxing services can provide a starting point for identifying potentially risky behaviour.
Domain names containing terms such as “pdf”, “convert”, “merge”, “file” or “free” may also be useful for exploratory analysis, although domain-name matching alone will inevitably produce false positives.
The goal should be to identify how the services are being used, rather than simply compiling a blacklist.
Talk to employees before reaching for the block button
Once potentially risky services have been identified, security teams should speak to the relevant users.
Ask a simple question:
“What are you using this service for?”
The answer may reveal a genuine business requirement.
If employees are repeatedly using free PDF editors because they lack an approved PDF editing application, the security problem may actually be a software-provisioning problem.
If staff are converting documents online because an internal application does not support a particular format, the organisation may need to address that workflow.
Blocking the website without addressing the underlying requirement will simply encourage employees to find another service.
Give employees a safe alternative
The most effective approach is usually a combination of technology, policy and education.
Organisations should consider:
- Identify commonly used online utilities. Use available security telemetry to determine which services employees are accessing.
- Understand the data being uploaded. A public-facing marketing document presents a very different risk from a payroll report.
- Provide approved alternatives. If employees need PDF editing, file conversion or malware analysis, give them tools they can use safely. Rather than employees using multiple free sites, subscribe to the best site and direct your users to that one and then block the other sites.
- Establish clear policies. Employees should understand what types of corporate information can and cannot be uploaded to external services.
- Use DLP and web controls where appropriate. Controls should focus on preventing sensitive information from leaving the organisation rather than indiscriminately blocking useful websites.
- Train staff on third-party services. Employees need to understand that uploading a document to a website is a form of data transfer.
- Regularly review shadow IT. The services employees use today may not be the services they use six months from now.
Convenience shouldn’t override data security
Online utility websites have become an ordinary part of how people work. They are easy to find, often free and can solve problems in seconds.
That convenience is precisely what makes them worth paying attention to.
A data breach does not always begin with an attacker breaking through a firewall. Sometimes it begins with an employee trying to convert a PDF.
The employee likely isnt doing anything malicious. They may simply be trying to get their job done.
For security teams, the challenge is therefore not just to block risky websites. It is to understand the workflows that drive employees towards them, provide secure alternatives and make sure staff understand the consequences of uploading business information to third-party services.
If your organisation has the visibility to do so, take a look at the freemium file-conversion, PDF-editing and web-based utility services your users are accessing. You may be surprised by what you find—and by the type of information being uploaded to them.