Dangerous Email Attachments: What to Watch For
Which email attachments are risky, how double extensions and disguised files trick people, and simple rules for opening attachments safely at home and at work.

Attachments are how many malware infections begin. A file that looks like an invoice, a CV or a delivery note can install software that steals passwords or opens the door to ransomware. Knowing which files are risky, and how they are disguised, prevents most of it.
Higher-risk file types
| Type | Examples | Risk |
|---|---|---|
| Programs and scripts | .exe, .scr, .msi, .bat, .js, .vbs | Run code directly |
| Disk images and archives | .iso, .img, .zip, .rar | Hide programs inside. See password-protected zips |
| Shortcuts | .lnk | Can launch hidden commands |
| Web files | .html, .htm | Open fake sign-in pages. See HTML attachments |
| Office documents with macros | .docm, .xlsm, older .doc/.xls | Run code if you enable content. See the macro warning |
| PDFs and images | .pdf, .jpg | Usually lower risk, but may link to phishing |
Disguises to watch for
- Double extensions: "Invoice.pdf.exe" shown as "Invoice.pdf" when extensions are hidden. Turn on "show file extensions" in your computer's settings.
- Icons that lie: a program can use a PDF or Word icon.
- Unexpected formats: an "invoice" arriving as an HTML file or zip.
Simple rules
- Do not open attachments you were not expecting, even from known senders, without checking.
- Never enable macros or content on documents from email.
- Preview files in the browser or email app where possible. See safe ways to open files.
- Keep your device and security software updated.
Opened one by mistake? Disconnect from the network and tell IT straight away. See opening an attachment by mistake.
Unsure about an email with an attachment? Paste the email text into CyberWatch AI Scan for a free check.
For more, see how phishing works in our complete guide.
Frequently asked questions
Are PDF attachments safe?
Usually safer than many file types, but PDFs can contain links to phishing pages and, rarely, exploit software flaws. Treat unexpected PDFs with caution.
What is a double extension?
A file named like 'invoice.pdf.exe', where the real type is the last part. Windows may hide known extensions, so it looks like 'invoice.pdf'.
Which file types should I never open from unknown senders?
Programs and scripts (.exe, .scr, .js, .vbs, .bat, .msi), disk images (.iso, .img), shortcuts (.lnk) and HTML files, plus Office documents that ask you to enable content.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission
- Mitigating malware and ransomware attacks, UK National Cyber Security Centre


