HTML Attachments That Open Fake Sign-In Pages
An email attachment ending in .html or .htm can open a convincing fake sign-in page on your own computer. How HTML attachment phishing works and why you should not open them.

Not all phishing links are links. Some phishing emails attach a small file ending in .html or .htm. When you open it, your browser shows a convincing sign-in page, often for your email or work account. Because the page runs from a file on your computer, some link filters never see it.
How it works
- An email arrives with an attachment such as "Remittance_Advice.html", "Invoice.htm" or "Voicemail.html".
- Opening it launches your browser with a sign-in page, sometimes pre-filled with your email address.
- When you type your password, the page sends it to the attacker.
- You may then be redirected to the real site so nothing seems wrong.
Warning signs
- The attachment ends in .html, .htm or .shtml.
- The address bar shows
file:///or a local file path, not a website. - You are asked to sign in to "view" a document, voicemail or payment.
Genuine invoices, voicemails and documents almost never arrive as HTML attachments. Treat them as phishing unless you have confirmed otherwise.
What to do
- Do not open unexpected HTML attachments.
- Report the email.
- If you entered your password, act now. See entered your password on a phishing page.
Got an email with an HTML attachment? Paste the email text into CyberWatch AI Scan for a free check.
Related: fake login pages. For more, see how phishing works in our complete guide.
Frequently asked questions
Why would an attachment be an HTML file?
Genuine emails rarely attach HTML files. Attackers use them because the fake page opens locally in your browser, which can avoid link filters.
The page showed my company logo. Is it real?
HTML attachments can load your company's logo or pre-fill your email address. That does not make them genuine.
What should I do if I entered my password?
Change it immediately from the real site, sign out of all sessions, and tell IT.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency


