Blog/Phishing

Dangerous Email Attachments: What to Watch For

Which email attachments are risky, how double extensions and disguised files trick people, and simple rules for opening attachments safely at home and at work.

CyberWatch AI1 October 2026 · 2 min read
A single metal paper clip on a grey surface

Attachments are how many malware infections begin. A file that looks like an invoice, a CV or a delivery note can install software that steals passwords or opens the door to ransomware. Knowing which files are risky, and how they are disguised, prevents most of it.

Higher-risk file types

TypeExamplesRisk
Programs and scripts.exe, .scr, .msi, .bat, .js, .vbsRun code directly
Disk images and archives.iso, .img, .zip, .rarHide programs inside. See password-protected zips
Shortcuts.lnkCan launch hidden commands
Web files.html, .htmOpen fake sign-in pages. See HTML attachments
Office documents with macros.docm, .xlsm, older .doc/.xlsRun code if you enable content. See the macro warning
PDFs and images.pdf, .jpgUsually lower risk, but may link to phishing

Disguises to watch for

  • Double extensions: "Invoice.pdf.exe" shown as "Invoice.pdf" when extensions are hidden. Turn on "show file extensions" in your computer's settings.
  • Icons that lie: a program can use a PDF or Word icon.
  • Unexpected formats: an "invoice" arriving as an HTML file or zip.

Simple rules

  1. Do not open attachments you were not expecting, even from known senders, without checking.
  2. Never enable macros or content on documents from email.
  3. Preview files in the browser or email app where possible. See safe ways to open files.
  4. Keep your device and security software updated.

Opened one by mistake? Disconnect from the network and tell IT straight away. See opening an attachment by mistake.

Unsure about an email with an attachment? Paste the email text into CyberWatch AI Scan for a free check.

For more, see how phishing works in our complete guide.

Frequently asked questions

Are PDF attachments safe?

Usually safer than many file types, but PDFs can contain links to phishing pages and, rarely, exploit software flaws. Treat unexpected PDFs with caution.

What is a double extension?

A file named like 'invoice.pdf.exe', where the real type is the last part. Windows may hide known extensions, so it looks like 'invoice.pdf'.

Which file types should I never open from unknown senders?

Programs and scripts (.exe, .scr, .js, .vbs, .bat, .msi), disk images (.iso, .img), shortcuts (.lnk) and HTML files, plus Office documents that ask you to enable content.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission
  3. Mitigating malware and ransomware attacks, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.