GrizzlyGrizzly
Recent phishing
Suspicious

Impersonating WeTransfer

Intent: Persuasion

  • Domain is not operated by WeTransfer
  • SPF record does not reference WeTransfer's infrastructure

WeTransfer download page listing shared files with a Download All button

Scanned 13 days ago · Sep 17, 2026, 17:21 UTC

Think this verdict is wrong?

Check a suspicious URL yourself — free to try.

Scan a URL
Suspicious: www.wetransfer-claims3748invoice.hasrhco.com — Grizzly