Fake PDF converter sites: 6 signs to spot them before you click
By the getPDF team · Published 11 October 2026
The short answer
A fake PDF converter gives itself away by asking for more than a file: it wants you to download an .exe or “converter app”, install a browser extension, paste a command, or hand over your email before the result. A real web converter returns a document (a .pdf, .docx or .jpg) and never needs you to install or run anything. If you already ran something from such a site, disconnect, scan, and change your passwords from another device.
Try it here, nothing is uploaded
The converter above runs in your browser: no download, no extension, no account. You drop images, you get a PDF back.
Why converters attract scammers
File conversion is one of the most searched jobs on the web, people searching for it are usually in a hurry, and many already expect to “download” something at the end. That makes a converter page an ideal disguise.
The warnings are on record. On 7 March 2025, the FBI’s Denver field office warned that criminals use free online document converters to load malware onto victims’ computers, leading to incidents such as ransomware. Its examples were ordinary jobs: turning a .doc into a .pdf, joining .jpg files into 1 PDF. The tools do the job they advertise, the FBI said, but the result can carry hidden malware, and the sites can scrape what people submit: ID numbers, dates of birth, banking and cryptocurrency details, email addresses and passwords (“FBI Denver Warns of Online File Converter Scam”, fbi.gov, checked on 11 October 2026).
Security firms reported the same pattern through 2025: Malwarebytes on 17 March 2025 described converter sites that push a downloadable “tool” or a browser extension; CloudSEK researchers on 15 April 2025 described lookalike copies of the PDFCandy converter that showed a fake “I am not a robot” check and then told visitors to run a PowerShell command; and BleepingComputer reported on AppSuite PDF Editor, a PDF editor promoted through Google ads that an update on 21 August 2025 turned into a password and cookie stealer.
The 6 signs
Sign 1: the result is a program, not a document. You asked for a Word file and you get contract_converter.exe, or a .zip with an .exe, .msi, .bat, .js or .scr inside. A converter’s job ends with a document: .docx, .pdf, .jpg, .png. Anything that would run when double-clicked is not a converted file. In Windows, turn on file name extensions (File Explorer, View, Show, File name extensions) so you see the real ending.
Sign 2: it asks you to install or run something. “Install our converter app for faster results”, “download the free tool”, or, newer, a fake robot check that tells you to press keys and paste a command into a Run box or a terminal. No web converter needs any of that. The last one is never legitimate on any site.
Sign 3: the address is almost right. A misspelled known brand (pdf-convrter, an extra letter, a hyphen in the wrong place), a known name on an unexpected ending, or a domain registered weeks ago. Read the address bar, not the logo: a logo is free to copy.
Sign 4: download buttons in the ad slots. Big green DOWNLOAD and START NOW buttons that sit in a box labelled “Advertisement”, or appear before your file is even converted. The real button appears after the job, next to your file’s name.
Sign 5: an extension you “must” add. “Add PDF Helper to continue.” Converter extensions pushed this way are often browser hijackers and adware, as Malwarebytes put it, and an extension can read the pages you visit. A web converter needs no extension.
Sign 6: your email before your file. “Enter your email to receive the converted document.” Some honest services email links, but a free converter that holds your result hostage for an address is building a mailing list at best, and a phishing list at worst.
One sign alone can be innocent; ads are how free sites pay their bills. Signs 1 and 2 are not innocent on any site.
If you already ran something
No shame: these campaigns are run by professionals, and the sites look convincing. Act calmly and in this order:
- Disconnect from the internet (Wi-Fi off or cable out), so whatever runs cannot send more.
- Run a full scan with up-to-date antivirus. On Windows, Microsoft Defender’s full scan is built in; an offline scan is stronger if it offers one.
- Change your passwords from another, clean device, starting with email (it resets everything else), then banking, then the rest. Turn on 2-step sign-in where you can.
- Call your bank if you entered card or bank details, or if the file you converted contained them.
- Remove any extension the site made you add, in the browser’s extensions page.
- Report it. The FBI asks people in the US to report to IC3 at ic3.gov; elsewhere, use your national police or cybercrime reporting point. At work, tell IT first, now, before step 3.
If the scan finds something it cannot remove, or the computer behaves strangely afterwards, get professional help rather than guessing.
How a real converter behaves
The safe pattern is short and the same on every honest site: you choose or drop a file, the page works, a button gives you a document of the type you asked for. No installer, no extension, no command, no email gate.
Tools that run in your browser go 1 step further: the file is converted on your device and never uploaded. On getPDF, nothing is ever offered as a program to download, and the site’s content security policy only lets the page talk to its own address. You can check both: the file you get ends in .pdf, .docx, .jpg or similar, and the Wi-Fi off test shows that nothing leaves your machine.
Try it here, nothing is uploaded
The honest part
Avoiding fake sites solves 1 problem. 2 others remain.
- A real site can still be breached. In July 2024, 2 genuine online PDF sites left 89,062 uploaded files open to anyone, as Cybernews reported. The guide on uploading to converters covers that risk.
- Any brand can be copied, ours included. A local tool removes the upload risk, not the need to check where you are. getPDF lives at getpdfs.app and nowhere else, never asks you to install anything, and never asks for an email.
A PDF itself can carry risks too, separate from the site it came from; can a PDF contain a virus explains what a file can and cannot do and how to look inside one first.
Questions
Can a PDF converter website give my computer a virus?
Not by converting a file in the page. The danger is what it makes you run: a downloaded .exe or installer, a browser extension, or a command it asks you to paste. A real web converter gives you back a document and never needs any of those.
Is a converter safe if it was the first result on Google?
Not automatically. In 2025, researchers found fake PDF tools promoted through search ads. Check the address bar before you drop a file: the domain should be the service you meant, spelled exactly.
I downloaded a file that ends in .exe from a converter. What now?
If you did not run it, delete it and empty the recycle bin. If you ran it, disconnect from the internet, run a full scan with up-to-date antivirus, and change your passwords from a different, clean device, starting with email and banking.
Are converters that run in the browser safer?
They remove 1 risk: your file is never uploaded. They do not protect you from a fake site. Only the address in the bar tells you which site you are on.
The tools for this job
Keep reading
- Is it safe to upload a PDF to an online converter? The honest answerUsually, but you cannot check it from the homepage.
- Can a PDF contain a virus? The real risk, and how to open one safelyYes, through scripts, launch actions and viewer exploits, though rarely.
- Prove a PDF tool is local: the Wi-Fi off test, and what the network panel showsPDF tools without uploading: turn Wi-Fi off and a truly local tool keeps working.
- PDF privacy and protection: the complete guideWhat a PDF password really protects, how true redaction works, what metadata leaks, and how to send files safely.