{"success":true,"data":{"id":"wetransfer-share-cross-domain","label":"Fake WeTransfer \"you received a file — download before it expires\" notice sent from a non-WeTransfer domain — credential-harvest and malware-delivery cross-domain phish exploiting expiration-pressure mechanic. Real WeTransfer mail originates from wetransfer.com / we.tl only.","description":"Fake WeTransfer \"you received a file — download via link before it expires\" notification sent from a non-WeTransfer sending domain (From / Reply-To / link domains do not align with wetransfer.com / we.tl) demanding the recipient click an off-domain link to download the supposedly shared file — credential-harvest and malware-delivery cross-domain phish. Real WeTransfer notifications come from wetransfer.com / @wetransfer.com with DMARC-aligned signing; cold emails from off-domain senders impersonating WeTransfer with off-domain file-download links are scams. WeTransfer impersonation is a high-volume file-share phishing lure tracked by Cofense 2024 PDC and Proofpoint 2024 — the expiration-pressure mechanic (\"file expires in 3 days\") drives high click-through. Distinct from dropbox-share-cross-domain (Dropbox), googledrive-share-cross-domain (Google Drive), and onedrive-share-cross-domain (Microsoft) — this targets the WeTransfer / file-transfer / expires-soon / download-via-link pretext with off-domain href. Detection: WeTransfer brand vocabulary + file-shared / expires-soon / download-via-link urgency + sender or link domain ≠ wetransfer.com / we.tl + no DMARC alignment. Trash score: +4. Source: GC1-R32; Cofense 2024 PDC quarterly report; Proofpoint 2024 State of the Phish; WeTransfer anti-phishing guidance; ENISA file-share impersonation patterns 2024.","tier":"warning","category":"other","isThin":false}}