Why this matters
Malicious attachments are a common way ransomware and password-stealing malware get onto computers. Most attacks need you to open the file and allow something to run, so a careful approach blocks them.
What you'll need
- The email with the attachment
- Up-to-date antivirus such as Microsoft Defender
Step-by-step instructions
Step 1
Confirm you were expecting it
Unexpected invoices, voicemails, scanned documents or "secure messages" are high risk. If in doubt, contact the sender by phone.
Step 2
Check the file type
Look at the file extension.
- Higher risk: .exe, .js, .vbs, .html, .htm, .iso, .img, .zip with a password, .one
- Lower risk but still check: .pdf, .docx, .xlsx, .jpg
Step 3
Preview before downloading
Outlook and Gmail can preview many documents in the browser without downloading them, which is safer.
Step 4
Never select "Enable Content" or "Enable Editing" without a reason
Office documents that ask you to enable macros or content to "view the document properly" are almost always malicious.
Step 5
Be wary of attachments that ask you to sign in
An attachment that opens a login page for Microsoft 365 or another service is a phishing attack.
Step 6
Report suspicious attachments
Report the email to your IT team rather than opening a file you are unsure about.
Summary
Being selective about which attachments you open, and never enabling macros on unexpected files, prevents most attachment-based attacks.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.