Blog/Phishing

"Enable Content": The Macro Warning You Should Never Ignore

A document says "Enable content to view". That yellow bar is one of the most important warnings on your computer. How malicious macros work and why you should refuse.

CyberWatch AI1 October 2026 · 2 min read
A woman working on a laptop showing a spreadsheet

You open an attachment and see a blurry document with a message: "This document is protected. Click Enable Content to view." A yellow bar at the top offers exactly that button. This is one of the oldest and most effective malware tricks. The document is not protected; clicking lets hidden code run.

How malicious macros work

  1. An email delivers a Word or Excel file, often an "invoice", "order" or "CV".
  2. The document opens in Protected View, a safe read-only mode.
  3. A fake message tells you to click "Enable Editing" and then "Enable Content".
  4. Once enabled, the macro downloads and runs malware, such as password stealers or tools that lead to ransomware.
Illustrative example · Text inside a document
This document was created in an earlier version of Office. To view the content, please click "Enable Editing" and then "Enable Content" above.
Red flag: any document that asks you to enable content to see it is almost certainly malicious.

The rule

Never click Enable Content on a document you received by email. If you genuinely need a macro-enabled file, confirm with the sender through another channel and ask your IT team.

For organizations

  • Block macros in files from the internet, which modern Office versions increasingly do by default.
  • Allow macros only from trusted locations or signed publishers.
  • Train staff with this exact example.

If you enabled content

Disconnect from the network and contact IT immediately. See opening an attachment by mistake.

Got a document asking you to enable content? Close it and paste the email into CyberWatch AI Scan for a free check.

Related: dangerous email attachments. For more, see how phishing works in our complete guide.

Frequently asked questions

What is a macro?

A small program inside an Office document that automates tasks. Attackers use macros to download and run malware when enabled.

Is 'Enable Editing' the same as 'Enable Content'?

No. Enable Editing leaves Protected View; Enable Content allows macros to run. Both should be avoided for unexpected documents from email.

Do genuine documents need macros?

Some internal business tools do, but documents arriving by email from outside your organization almost never need them.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. Mitigating malware and ransomware attacks, UK National Cyber Security Centre
  3. Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.