The impact of infected attachments describes what happens to data and devices. The consequences describe what happens to people: work that grinds to a halt, payments that end up in the wrong place, clients who need an explanation, and evenings spent putting the pieces back together.
It is a useful distinction, because an attachment feels like a small thing: one file, one click, a few seconds. What follows can take up weeks. This post tries to describe it honestly, without dramatising and without downplaying.
It expands on the recommendation on not opening unknown attachments.
A realistic scenario
John runs a small plumbing and heating business: two engineers, a part-time office assistant and one office computer that does a bit of everything. It holds the email, the quotes, the accounts, the client folders and a shared folder that everyone also uses from the laptop.
One Monday morning an email arrives that seems to come from the wholesaler he buys his materials from: “Please find attached the March invoice, kindly check the amount.” John really is expecting an invoice from that supplier, so he opens the file without thinking twice.
The document opens almost empty. A message asks him to “enable content” to view it properly. John clicks, the page stays blank, he closes it assuming it is a glitch and heads off to a job.
That click has started malware, a program designed to damage a device, spy on it or take control of it. For two days, nothing visible happens.
On Wednesday, the files in the shared folder have strange names and will no longer open. A demand for payment appears on the screen. That same afternoon a client rings: he has received an email from John with “new bank details” for the deposit.
From this point on, the consequences spread across five planes.
1. Operational consequences: when the office stops
A practical example
The quotes in progress, the records of installed systems, the photos from jobs and the paperwork for applications are all in the shared folder. They have been encrypted by ransomware, a type of malware that makes files unreadable and demands a ransom to release them. The office computer has to be switched off and disconnected, and everything that ran through it stops too.
Possible effects
- quotes due to go out that can no longer be found;
- appointments and call-outs to reorganise, because the diary was on that computer;
- invoices that should have been issued put on hold;
- the engineers’ laptop to be checked, because it used the same folder;
- days spent rebuilding instead of working.
Why it matters
In a small business, a single computer often carries most of the admin work. When that computer stops, the office stops. If there is a copy of the files kept separately, recovery is measured in days; if there is not, some documents have to be rebuilt by hand and others are gone. The mechanism is explained in the post on ransomware and personal files, and it applies to work files just as much.
2. Financial consequences: when the damage becomes a number
A practical example
The malware has also collected the login details — usernames and passwords — saved on the computer, including the one for the email account. Whoever now holds them writes to John’s clients with different bank details. One client pays the deposit into the wrong account. Meanwhile, the wholesaler’s genuine invoice sits unpaid because nobody can check it.
Possible effects
- deposits and payments diverted to accounts whose owner is unknown;
- delays in getting paid and in paying suppliers;
- technical support costs to clean up and reinstall the computers;
- in some cases, replacing drives or devices;
- lost working hours, which for a tradesperson are hours that cannot be billed;
- money that, sometimes, cannot be recovered.
Why it matters
The ransom demand is the most visible item, but it is rarely the most expensive. Paying does not guarantee getting the files back, and the authorities generally advise against it. More often, the money is lost through diverted payments, idle days and technical support. As with any fraud, noticing early matters more than most people think: for the first steps, see what to do after opening a suspicious attachment.
3. Legal and regulatory consequences: when your clients’ data is involved
A practical example
John’s folders hold his clients’ names, addresses, phone numbers and tax reference numbers, floor plans of their homes, photos of the rooms he worked in, and copies of identity documents attached to applications. Some malware copies files before encrypting them: it may not have happened here, but it has to be assessed.
Possible effects
- a duty to assess what happened and, where the conditions apply, to notify the relevant data protection authority and the people affected;
- responsibility towards clients for protecting the data they entrusted to you;
- the need to keep the email and any information that helps reconstruct what happened;
- formal steps to handle within tight deadlines, just when the office is at a standstill;
- conversations to have with the firms you work for as a subcontractor and, if you have one, your insurer.
Why it matters
When your folders hold other people’s data, an opened attachment stops being a problem with your own computer. A floor plan or a photo of a living room says a great deal about a home and the people who live in it. This section describes the general picture and is not a substitute for legal advice: if a breach involves other people’s personal data, it is worth speaking to a professional or to your data protection contact.
4. Reputational consequences: when trust starts to crack
A practical example
More emails go out from John’s mailbox, with the same fake invoice attached, to clients, suppliers and fellow tradespeople. They come from an address people know and trust: that is exactly what makes them convincing.
Possible effects
- clients asking for explanations, some of them understandably worried;
- suppliers putting orders on hold until the situation is clear;
- contacts who open the attachment “from John” and end up with the same problem;
- the need to warn everyone and explain what happened;
- for a while, suspicion of every email that comes from the business.
Why it matters
In a business that lives on word of mouth, trust is a concrete part of the work. It is rebuilt over time and through openness: warning your contacts early is part of the response, not an admission of guilt. To understand how compromised accounts are used, see the post on messages sent in your name.
5. Personal consequences: when it weighs on the person
A practical example
John spends his evenings on the phone with clients and with the IT technician. He keeps going back over that Monday morning. He wonders what else has been copied, and whether the wholesaler’s next email will be genuine.
Possible effects
- prolonged stress and a feeling of having lost control;
- personal and family time swallowed up by recovery;
- a sense of guilt towards the staff and clients involved;
- private documents exposed, if some were stored on that computer as well;
- distrust of every attachment, including legitimate ones;
- greater exposure to people who exploit fear, for example with fake virus warnings or bogus “file recovery” offers.
Why it matters
This is the least visible consequence and often the longest. It is worth saying clearly: if this has happened to you, it is not because you were naive. John was expecting an invoice, the email looked right, and whoever built it was counting on exactly that. Fake invoices work because they look like everyday business.
| Plane | What changes | How long it lasts |
|---|---|---|
| Operational | Files encrypted, computer switched off, diary and quotes unavailable | Days to weeks |
| Financial | Diverted deposits, late payments, support costs | Weeks, not always recoverable |
| Legal | Assessment and, if needed, notification over clients’ data | Tight deadlines, formal steps |
| Reputational | Trust of clients and suppliers to be rebuilt | Months |
| Personal | Stress, time taken from family, guilt | Variable, often the longest |
The cost no one budgets for: recovery time
The ransom and the diverted payments are fairly easy to put a figure on. Time is much harder — and it is almost always the heaviest item.
An indicative estimate, based on how these recoveries usually unfold in a small business:
| Activity | Indicative time |
|---|---|
| Isolating the computer and working out, with a technician, what happened | A few hours to a day |
| Restoring files from a backup copy, if one exists and was kept separate | Half a day to a few days |
| Rebuilding quotes and documents without a copy | Weeks, and not everything comes back |
| Reinstalling the computer and the business software | 1–2 days |
| Changing passwords from a clean device and checking the mailbox | 2–4 hours |
| Warning clients, suppliers and contacts | 1–3 hours, plus the phone calls that follow |
| Assessments and formal steps over clients’ data | Days, with deadlines to meet |
| Checks on accounts and sign-ins over the following weeks | Ongoing |
These are hours that were never on the calendar, taken away from jobs or from family, and packed into a period when you are already under pressure.
The comparison is telling: checking an unexpected invoice with a phone call takes a minute; a separate copy of your files only has to be set up once.
The consequences that fall on other people
An opened attachment rarely stays the problem of the person who opened it.
- Your clients may pay into the wrong account, and their data may have been exposed.
- Your suppliers and fellow tradespeople receive convincing emails in the name of your business, and some of them open the attachment.
- Your staff lose days of organised work and end up handling difficult phone calls.
- Family members, if the same devices or the same home network are used, can be drawn in.
- The people whose data was on file face an exposure they had no say in.
This is why, in the Cyber Welfare Framework, personal security is not treated as a purely private matter: every attachment you check also protects the people behind it.
How this ties back to the recommendation
All of these consequences start from the same place: an attachment opened without really knowing who sent it and why.
Not a serious lapse, and not a computer left without protection. An ordinary gesture, made in a hurry, on a file that seemed part of the routine. It is the same lever used by emails pretending to be your bank: imitate a sender people expect, so that checking feels unnecessary.
That is why recommendation R17 matters more than it seems: it is the point at which an incident can stop before it starts.
How to reduce the risk
- Treat every unexpected attachment as a question, not a task. If an invoice, a delivery note or a document was not announced, check with the sender through another channel — for example, a call to the number you already have.
- Learn to recognise the most common warning signs, such as requests to “enable content” or password-protected archives: you will find them in the signs of a dangerous attachment.
- Keep a copy of important files separate from the computer, on a disconnected drive or on a storage service that keeps earlier versions. The recommendation on backing up photos and videos explains how, and it applies to work documents too.
- Leave updates switched on: many malicious attachments exploit flaws that have already been fixed. See keeping your software up to date.
- Do not turn off the protections your email service and operating system provide: understanding how attachment scanning works helps you make good use of them, without expecting them to be infallible.
- Decide in advance who to call if something goes wrong: a technician, a colleague, your data protection contact. Deciding beforehand saves hours afterwards.
Quick checklist
- ☐ I know which files would bring my work to a halt if they became unreadable
- ☐ I have a copy of my important documents kept separate from the computer
- ☐ I check invoices and documents I was not expecting through another channel
- ☐ I know who to turn to if my clients’ data were exposed
- ☐ I have a way to warn clients and suppliers quickly without using my email
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Connecting an everyday gesture, opening an attachment, to concrete effects on work, money and relationships |
| Skills | Telling the five planes of consequence apart and knowing what recovery times to expect |
| Secure Behaviour | Checking before opening and acting early: prompt action reduces almost every consequence described here |
Reference level: FL2 — Beginner. This is the level at which security stops being an abstract rule and becomes a choice with a clear reason behind it.
Conclusion
A malicious attachment does not produce “a virus on the computer.” It produces an office at a standstill, deposits paid into unknown accounts, clients to reassure, and a stretch of time spent wondering what else has been seen.
The good news is that most of these consequences can be reduced with habits within anyone’s reach: checking unexpected attachments before opening them, keeping a separate copy of important files, and letting updates do their work. If you would like to see where you stand with your digital habits in general, you can take the digital resilience self-assessment.
Something to think about. If the files on your computer became unreadable tomorrow, which ones would you miss first — and where is their copy?
Related resources
Short guides from the Resources section, for anyone who wants to focus on a single aspect:
- How to recognise phishing when it is built to be convincing
- Scareware: the warning that is itself the attack
Related content
- Not opening unknown attachments — the recommendation this belongs to
- Impact of infected attachments — the technical plane: confidentiality, integrity, availability
- What to do after opening a suspicious attachment — the steps to take, in order of priority
- Malware in email attachments — how fake invoices and other disguises work
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



