The Quiet Death of ‘Just Send Me the File’

Every business, every day, has the conversation that ends with ‘just send me the file.’ The way the file moves has not changed in 30 years. That is starting to change, slowly.

A single brass envelope fading into smoke on dark wood, dim warm amber side light, deep navy shadows, no people, no logos.


Every business in the world, at some point every day, has the conversation that ends with “just send me the file.” The file is usually a contract, a PDF, a photo of a receipt, a video, or a spreadsheet that is too big to print.

The way the file moves has not changed in 30 years. Email attachment. Sometimes a shared link. Maybe, if the company is large enough, an FTP server that no one has the password to anymore. The conversation has not changed either. The file moves. The conversation ends. The risk gets ignored.

That is starting to change. Slowly.

What the file actually is

Abstract inbox icon with files flying in and out, some marked with red warning symbols, dark background with cyan and amber accents.
Email becomes the most popular file transfer tool in the world. It is also the most surveilled.

A file is not just data. A file is a context. It usually contains more than the sender realizes. A PDF contract contains the names of the lawyers, the parties, the bank account, the wire instructions. A photo of a receipt contains the GPS coordinates of the restaurant, the timestamp, the device model. A spreadsheet contains the formula dependencies, the version history, the comments.

Email treats this context as the cost of doing business. The file goes out. The metadata goes with it. The recipient has a copy. The sender has a copy. The mail server has a copy. The backup has a copy. The cloud archive has a copy. Five copies minimum, and the sender has not consented to any of them.

Why email is still the default

Three reasons, in order of importance.

  1. It works. Email works. It has worked since 1971. The recipient does not need an account, an app, a phone number, or a working internet connection to receive an email.
  2. It is universal. Every person and every business in the world has an email address. There is no other channel with that reach.
  3. It is free. Sending a file is not a paid feature of email. The cost of the attachment is absorbed by the mail server the user already pays for.

All three of those advantages are real. None of them are good reasons to keep using email for files in 2026. They are reasons it is hard to switch, not reasons it becomes the right tool.

What the alternatives actually do

There are about a dozen “secure file transfer” products that have existed for 20 years. Most of them are bad. A few of them are good. None of them have replaced email. Here becomes the landscape in 2026.

Consumer-grade file sharing

Dropbox, Google Drive, OneDrive, iCloud. These work for personal file sharing. They do not work for “send this to a client who uses Outlook” because the recipient needs an account, and most recipients do not want one.

Link sharing becomes the workaround. The sender uploads to a personal drive, generates a link, emails the link. The recipient downloads. This is better than an attachment for size, worse for control. The link is guessable in many implementations. The link is forwarded. The link is searched.

Enterprise file transfer

Box, Egnyte, ShareFile, Citrix ShareFile. These were built for the “send a 4GB file to a customer” problem. They work. They are clunky. They are not used by individuals, only by companies that have standardized on them.

The friction serves as the auth flow. The recipient gets a link, has to verify their email, sometimes has to create an account, sometimes has to install a plugin. The share rate drops by an order of magnitude compared to email.

Secure file transfer (the right thing)

Tools like Tresorit Send, Wormhole, Onetime Secret, Magic Wormhole, and a dozen newer ones in the same space. End-to-end encrypted, recipient does not need an account, file is destroyed after download or after a time limit.

These are the right technical answer. They are not the right product answer, because the product is “send a file securely,” and most people do not think they need to send a file securely. They think they need to send a file.

Messaging apps

Signal, WhatsApp, iMessage, Telegram. These are the file transfer tool of choice for billions of people, and the corporate security team is, in most cases, looking the other way. The file gets sent. The audit log does not show it. The DLP system did not see it.

This is not a recommendation. It is a description of what is happening.

What the actual risks are

The risk of a file transfer is not the file itself. It is what is around the file.

  • Metadata. Who sent it, to whom, when, from what device, with what subject line, with what prior conversation attached. The metadata is often more sensitive than the file.
  • The trail. The file lives on the sender’s outbox, the recipient’s inbox, the mail server, the backup, the archive, the e-discovery system. Six months later, it can be retrieved by anyone with a subpoena. Three years later, it is in a different company’s archive.
  • Compromised accounts. Email accounts are compromised at scale. The most common BEC attack is “send a file from the CFO’s account asking for a wire transfer.” The file runs as the pretext.
  • Attachments that are not what they say they are. PDF, JPEG, DOCX. The file extension stands as the visible thing. The actual file is whatever the OS or the mail client decides to render. Macros, scripts, embedded executables. The mail client blocks some of these. Not all.

What the death of “just send me the file” actually looks like

It does not look like one product winning. It looks like the gradual replacement of the attachment with a link. The link is to a service that has a session, has a permission, has an audit log, has an expiration. The link is more than a file. It is a file with a wrapper.

Google’s effort with Material 3 in Android, the rise of shared workspaces (Notion, Coda, Linear), the move of small business contracts to DocuSign and similar, the quiet replacement of email attachments with Notion pages, the rise of ephemeral link services like Wormhole and Onetime Secret. None of these are “the replacement.” All of them are taking share from the attachment.

What to do about it (if you run a business)

  1. Pick a default file transfer tool and use it. Not “let people use whatever they want.” A real choice, with a real audit log, with a real retention policy. Box, Egnyte, ShareFile, even Dropbox Business. Pick one.
  2. Forbid the use of personal email for business files. This is a basic control. Most companies do not enforce it.
  3. Audit your DLP for file transfer. If your DLP cannot see where the files are going, it cannot enforce the policy. The biggest gap in most DLP systems runs as the “share link to a file” flow.
  4. Train on the BEC pattern. “The CFO emailed me asking for a wire transfer and attached the new bank details” sits as the most common attack on small and mid-size businesses. The training sits as the cheapest control you can add.
  5. For the most sensitive files, use ephemeral links. Wormhole, Onetime Secret, or a similar tool. The file is sent, downloaded once, destroyed. The audit log becomes the URL.

What to do about it (if you are a person)

  1. Do not send sensitive files over email. The mail server is a copy. The backup is a copy. The recipient’s mail server is a copy. Three copies minimum, and none of them are under your control.
  2. Use a link with an expiration. Google Drive, Dropbox, OneDrive all do this. The link expires in 7 days, 30 days, or whatever. The file does not live forever in someone’s inbox.
  3. For the very sensitive, use Signal or Wormhole. The file is encrypted, ephemeral, and not on a server that is going to be subpoenaed next year.
  4. Check the metadata before you send. The photo you took of the contract has your GPS coordinates. The PDF has the author name. Strip what does not need to be there.

The bottom line

Email stands as the most popular file transfer tool in the world. It is also the least auditable, the least ephemeral, and the most likely to be in a future breach. The replacement is not one product. It stands as the slow accumulation of small choices: links instead of attachments, expiration instead of forever, encrypted instead of plaintext.

The conversation that ends with “just send me the file” is not going away. The mechanism of how the file moves is. That runs as the quiet death of the most common thing in business.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading