Every day, billions of files are shared over the internet using methods that are laughably insecure. This guide explains why — and what to do instead.
8.2 billion
Records exposed in data breaches last year
68%
Of breaches involve a human element — a forwarded file, a wrong inbox
$4.88M
Average cost of a data breach in 2024 (IBM)
These are the six most popular ways people share files — and a real-world scenario showing exactly how each one can go catastrophically wrong.
Real-world scenario
"A law firm emails a client's signed contract. The email bounces through six different mail servers in three countries before arriving — every hop a potential interception point. The attachment sits in both the sender's Sent folder and the recipient's inbox, unencrypted, forever."
Real-world scenario
"A recruiter shares a candidate's resume via a "anyone with the link" Google Drive URL. That link gets forwarded, shared in a Slack channel, and eventually indexed by a search engine. Three years later a stranger finds the candidate's home address and salary history."
Real-world scenario
"An accountant DMs a client's tax return PDF over WhatsApp. The file is automatically backed up to iCloud on both devices, cached on WhatsApp's servers, and synced to every other device signed into the same Apple ID — including the client's teenager's iPad."
Real-world scenario
"A hospital employee copies patient records to a USB drive to take home for a weekend project. The drive falls out of their bag on the subway. A stranger plugs it in out of curiosity. HIPAA violation. $1.9 million fine. Career over."
Real-world scenario
"A consultant uses an airport's free Wi-Fi to FTP a proposal to a client. A threat actor running a Wi-Fi honeypot captures the entire transfer in seconds. The proposal — containing the client's unreleased product roadmap — appears on a competitor's desk by Monday."
Real-world scenario
"An employee saves a confidential merger document to the company's shared network drive "just temporarily." A disgruntled colleague in a different department stumbles on it. By 9 a.m. it's in the hands of a journalist. The acquisition collapses."
File breaches almost always fall into one of three categories. Understanding them is the first step to protecting yourself.
01
Your file travels across dozens of routers and switches between you and the recipient. Any unencrypted hop is an opportunity for interception. HTTPS helps, but only up to the server — after that, the file often sits unencrypted.
02
Once a file lands on a server — yours, theirs, a mail relay — it usually sits in plaintext storage. A single database compromise or misconfigured S3 bucket exposes everything. Most consumer services do not encrypt at rest.
03
Permanent links, shared passwords, and over-permissioned accounts mean the right person gets access today — and the wrong person gets access indefinitely. There is no expiry, no audit, and no way to revoke.
CipherSend was designed from the ground up to eliminate all three attack surfaces — not as an afterthought, but as the core architectural principle.
Every file is encrypted on your device before it ever leaves. The server stores only ciphertext — even a full breach of our infrastructure exposes nothing readable.
Each file gets its own randomly-generated encryption key. Compromising one file is mathematically impossible to leverage against any other.
Set links to expire in 1 hour, 24 hours, or up to 30 days. Once expired, the download link returns 404 — even if someone bookmarked or forwarded it.
Add a one-time password to any share. Even if your email is intercepted, the file stays locked without the passphrase you share through a separate channel.
Every download is logged with timestamp and IP. Know exactly who accessed your file — and when. Share the audit log with compliance teams in one click.
We never store unencrypted files. Our servers are architected so that database administrators, engineers, and even court orders cannot produce the original file contents.
Head-to-head against the alternatives
| Feature | Drive/Dropbox | CipherSend | |
|---|---|---|---|
| End-to-end encryption | |||
| Encrypted at rest | |||
| Link expiration | Partial | ||
| Password protection | Partial | ||
| Download audit log | Paid only | ||
| Instant revocation | |||
| No provider scanning | |||
| No account for recipient |
No PhD in cryptography required.
Drag and drop any file up to 5 GB. It is encrypted client-side before upload begins.
Choose expiration, download limits, and an optional password. You decide how long the file lives.
CipherSend emails a branded download link directly to your recipient — no account required on their end.
Monitor downloads in real time. Revoke access instantly if plans change.
It takes 30 seconds to create an account and send your first encrypted file. Free, forever, for everyday use.