WeTransfer automatically checks whether passwords associated with accounts have appeared in known data breaches.
If your password matches one that has been exposed in a breach from another website or service, we'll block access to your account until you create a new password. This helps protect your account from unauthorized access.
Important: This doesn't necessarily mean your WeTransfer account was breached. It means the password you were using has appeared in a known data breach elsewhere.
How does WeTransfer know?
We compare account passwords against databases of passwords that have been exposed in previous data breaches across many websites and applications.
If we detect that your password has been compromised, we notify you so you can secure your account.
What should I do?
We recommend taking these steps:
- Reset your WeTransfer password using the link in the security email or by signing in and going to Profile & Security in your account settings.
- Choose a new, unique password that you don't use for any other website or service.
- If you used the same password elsewhere, change it on those accounts as well.
- Enable Two-Factor Authentication (2FA) on your WeTransfer account for an extra layer of security.
Can I find out where my password was exposed?
You can check whether your email address has appeared in known data breaches using the Have I Been Pwned service:
This can help you identify whether your credentials may have been exposed in a previous breach.
I wasn't expecting this email. Could it be a phishing attempt?
If you're ever unsure about an email, avoid clicking links and instead sign in directly to your WeTransfer account to manage your password from our account settings.