Blog/Phishing

Opening an Attachment by Mistake: What to Do

You opened an email attachment and now suspect it was malicious. What to do right now: disconnect, report, avoid making it worse, and check your device and accounts.

CyberWatch AI1 October 2026 · 2 min read
A woman typing at a desk in a bright office

You opened an attachment, maybe clicked "Enable Content", and now something feels wrong. Do not panic, and do not hide it. What you do in the next few minutes matters more than the click itself.

At work

  1. Disconnect from the network: turn off Wi-Fi or unplug the cable.
  2. Do not switch off unless IT tells you to; they may need to investigate.
  3. Tell IT or security immediately, with the email, the time and what you did.
  4. Do not forward the attachment to colleagues.
  5. Follow IT's instructions on passwords and next steps.

At home

  1. Disconnect from the internet.
  2. Run a full scan with reputable security software.
  3. From a different, clean device, change passwords for email and banking, and sign out of all sessions. See password change order.
  4. Watch your accounts for unusual activity.
  5. If in doubt, get the device checked or reset it after backing up personal files. See password-stealing malware.

Do not type new passwords on the device that may be infected. Use a clean device.

Signs something ran

  • A window flashed and closed.
  • The document asked you to enable content. See the macro warning.
  • New programs or browser extensions appear.
  • The device becomes slow or security software is disabled.

Want to check the email you received? Paste its text into CyberWatch AI Scan for a free check.

For more, see how phishing works in our complete guide.

Frequently asked questions

Should I turn off my computer?

At work, disconnect from the network but ask IT before switching off, as they may need to investigate. At home, disconnecting from the internet is the priority.

What if nothing seemed to happen?

Malware often runs silently. Still report it and let IT or security software check the device.

Will I get in trouble at work?

Good organizations want quick reports. Reporting immediately limits damage and is the right thing to do.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission
  3. Mitigating malware and ransomware attacks, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.