Skip to main content

Good morning! 

 

Yesterday I noticed that Salesforce had rolled out this 'Malicious Files' list view, but it seems to be listing most, if not all, of our files as malicious (for context, they are largely just regular PDFs uploaded by me to attach to opportunities for backup & documentation). Does anyone know what is causing these to be in this list view? Is there a different way to upload files that I should be using?  

 

Thank you for your help. 

 

#Salesforce Admin  #Security

2 answers
  1. Sep 2, 1:05 PM

    Hi Levi, good news first: this is not something you did, and your upload method is fine. Salesforce turned on native File malware scanning (Spring 26, still Beta) on by default, and the Malicious Files list is simply where any file the scanner flags shows up. Flagging is the scanner's call, not how you attach the file, so there is no different upload method that avoids it. 

     

    Why plain PDFs get caught: PDF malware heuristics are very sensitive to embedded active content, JavaScript, form logic, or launch actions, which a lot of system-generated backup PDFs carry even though they are perfectly benign. On a Beta at scale, that produces exactly the false-positive wave you are seeing (even Adobe's own PDFs have been flagged by scanners before). 

     

    What to do: 

    1. Do not worry about the files. Flagging does not delete or block them, they stay fully accessible. The list is a review surface, not a quarantine. 

    2. In Setup, open the Salesforce Files security settings, that is where the malware scanning is controlled if the volume is disruptive. 

    3. Since it is a Beta mass-flagging clean files, log a Salesforce Support case reporting the false positives so it gets tracked and tuned. 

     

    if this helps, please mark it as the Best Answer so it helps the next person, thanks 🙂

0/9000