When people talk about dangerous attachments, the most common reaction is “it was only a PDF”, or “there’s nothing important on my computer anyway”. Both are understandable, but they start from the idea that the damage stays locked inside that one file. An infected attachment is a file that carries malware — a program written to make your device do something you never decided. It isn’t prepared for you in particular: it is sent to thousands of addresses, with names like “invoice”, “payment reminder” or “shared document”, counting on someone opening it in a rushed moment.
The more useful question is a different one: if that file did what it was built to do, what would be touched?
This post answers it by looking at the impact of infected attachments through the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that the damage from an attachment is never of just one kind, and rarely stops at the file you opened.
It expands on the recommendation about not opening unknown attachments: if you don’t know where a file comes from, or something doesn’t feel right, it’s better to delete it without opening it.
Three questions to measure an impact
Before getting into the details, it’s worth having the right questions at hand. For any device you read your email on — and not only when a suspicious message arrives — they are these:
- What could a program running here without my permission read or take away? — this is the confidentiality question.
- What could it change, encrypt or control in my name? — this is the integrity question.
- What would I no longer be able to do if this device, or the files it reaches, became unusable? — this is the availability question.
Applied to the laptop you work on, connected to the office’s shared folders and to your backup at home, these three questions almost always produce the same answer: a lot. Applied to an old computer used only for browsing, the answer seems modest — until you discover that its browser remembers the passwords to all your accounts. That is where the maths changes: the impact isn’t measured on the file you opened, but on everything the device that opened it can reach.
1. Confidentiality: your passwords and files stay yours
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. An infected attachment hits it directly, because many harmful programs are built precisely to look for and copy whatever is valuable on a device, without being noticed.
A practical example
You receive an email from a sender you don’t know, with a document called “updated quote”. You open it; the document looks blank or garbled and invites you to “enable content” to view it. That button switches on macros — small programs built into documents that can carry out actions on your computer. Nothing changes on screen, but in the meantime a program may have started working in the background.
What the incident looks like
A widespread type of malware, known as an infostealer (literally, an “information thief”), gathers what it finds within minutes: the passwords saved in your browser, session cookies — the small files that keep you signed in to websites without typing your password again — the documents in your most-used folders, sometimes chats and address books. Everything is sent elsewhere. Nobody needs to change a single file: the copying alone is already a harm, and it is the one that goes most unnoticed, because the device carries on working as before.
What to watch for
- a document that, as soon as it opens, asks you to enable content, macros or editing before you can read it;
- a file that won’t open, or opens blank, without any clear error;
- sign-in notifications on your accounts from places or devices you don’t recognise, in the days that follow;
- password reset requests you didn’t start.
What to do
If an attachment comes from someone you don’t know, or from a known contact but out of the blue, don’t open it: check with the sender through a different channel from that same email. If you have already opened it and it asked you to enable something, treat the passwords saved on that device as exposed: change them from another, clean device, starting with your main email. The steps, in order, are set out in the post on what to do after opening a suspicious attachment.
2. Integrity: your files and device stay as you left them
Integrity is the guarantee that data, or a system, isn’t altered by anyone without the right to do so. Here an infected attachment weighs in a different way: it’s no longer about what someone can see, but about what they can change or control on your device, as if they were you.
A practical example
A compressed archive — a single file that bundles several others, often a .zip — attached to a fake delivery notice contains a file that, once opened, installs remote access: a program that lets someone else use your computer from a distance, see the screen, move files and install more software. The device doesn’t look broken: it simply obeys two people instead of one.
What the incident looks like
Files can be encrypted, meaning scrambled so they can’t be read without a key that only the attacker holds. They can be altered: a document with changed payment details, an invoice with different amounts. The device can be used to send emails in your name to your contacts, with new infected attachments that seem believable precisely because they come from you — the subject of messages sent in your name. And security settings can be changed, so that the system’s own defences stop reporting what is going on.
What to watch for
- programs or icons that appeared without you installing them;
- the system’s protection shows as switched off, and it wasn’t you;
- the pointer moves or windows open while you aren’t using the computer;
- contacts telling you about strange emails, with attachments, sent from your address.
What to do
Keep your operating system and programs up to date: many infected attachments exploit flaws that have already been fixed, and keeping your software up to date closes those doors without you having to remember. Where possible, work from an account without administrator rights — one that isn’t allowed to install programs or change system settings: a file opened by mistake will be able to do far less. If you notice signs of someone else in control, disconnect the device from the network before anything else.
3. Availability: your files, device and network work when you need them
Availability is the guarantee of being able to use your data and your tools at the moment you need them. It’s the easiest impact to recognise, because it shows up as a locked door: the files are there, but they won’t open.
A practical example
On Monday morning you switch on your computer and find every folder full of files with an unfamiliar extension — the few letters after the dot that tell the system what kind of file it is — plus a message demanding payment to give them back. This is ransomware, malware that encrypts files and demands a ransom. The starting point is often an attachment opened days earlier, which has been preparing the ground in the meantime. How this threat works on personal files is explained in the post on ransomware and personal files.
What the incident looks like
The lockout rarely stays on a single computer. A harmful program looks for whatever the device can reach: the office’s shared folders, a network drive — a disk connected to the router and used by several people — the backup drive left permanently plugged in. It may try to spread to other devices on the same network, at home or at the office. For anyone who works, that means coming to a stop, with colleagues locked out even though they opened nothing. And paying the ransom offers no guarantee of getting the files back.
What to watch for
- files that no longer open and have changed name or extension;
- a computer that has suddenly become extremely slow, with the disk constantly busy;
- on-screen messages asking for payment to unlock data or the device;
- the same problem appearing on other computers or in shared folders.
What to do
Keep up a habit of backing up photos and videos and documents, with at least one copy that is disconnected from the computer when you aren’t using it: it is the only concrete guarantee that you can start again. If you see the signs of a lockout, disconnect the device from the network and from the backup, don’t keep switching it off and on, and ask for help before trying fixes found in a hurry.
| Aspect | What an infected attachment can do | Why it matters |
|---|---|---|
| Confidentiality | Copies saved passwords, active sessions, documents, address books | The harm happens without visible traces, and hits accounts that have nothing to do with the email |
| Integrity | Encrypts or alters files, hands control of the device to others, sends messages in your name | You can no longer trust what the device shows or does |
| Availability | Locks files and the device, reaches shared folders and other computers on the network | Stops personal and work activities, even for people who opened nothing |
One scenario that brings them together
Mark runs a small practice with two colleagues. One Friday afternoon an email arrives from an address he doesn’t know: “Payment reminder — invoice attached”. He opens it to work out which invoice it means, and the document asks him to enable content.
Over the weekend, in sequence: the passwords saved in his browser and his clients’ documents are copied (confidentiality); emails with the same attachment go out from his address to several suppliers, and remote access is installed on his computer (integrity); on Monday the practice’s files and the shared folder are encrypted, including the backup drive that was still plugged in (availability). Three different impacts, a single cause: a file opened out of conscientiousness, from a sender nobody had ever heard of.
The impacts that show up later
Not every effect appears right away. Some develop over time, which is why “I opened it and nothing happened” isn’t a reliable check.
- Silent copying. Anyone stealing information has every reason to stay out of sight. The first sign may come weeks later, when a copied password is used on an account you would never have linked to that attachment.
- Access that stays open. Installed remote access, or a copied session, keeps working even after the file has been deleted, until it is explicitly removed or signed out.
- The device works for someone else. A compromised computer can be used to send unwanted messages or to attack other systems, without its owner knowing.
- Data used to make another message believable. Client names, ongoing conversations, amounts: all of it helps build emails that look like the continuation of a real exchange, sent to you or to your contacts.
This isn’t a reason to live on high alert. It’s the reason protection has to be preventive: not opening what you weren’t expecting, updating, and keeping a disconnected backup reduce all four of these effects, including the ones you’ll never see.
Not all devices weigh the same
The impact depends on what a device holds and on what it lets someone reach.
| Where the attachment is opened | Main impact | Why |
|---|---|---|
| Work computer in a small business | All three, with effects on others | Holds client and supplier data, and is connected to shared folders |
| Computer with the backup always plugged in | Availability | Ransomware also encrypts the copy that was meant to save you |
| Family computer at home | Confidentiality and integrity | Saved passwords for several people, personal documents, shared accounts |
| Computer connected to a network drive | Availability and integrity | The damage spreads to the files of everyone who uses that drive |
| Phone | Confidentiality | Email, messages, verification codes and payment apps all sit in the same place |
On a phone, the signs of an infection differ from those on a computer: you’ll find them in the guide to spotting the signs of malware on your phone.
Why a file that looks harmless still matters
Many instinctive reassurances don’t reduce the impact, because they say nothing about what the file actually does.
| What reassures you | Why it isn’t enough |
|---|---|
| “It’s a PDF, not a program” | A document can also contain links, macros or requests to download something else |
| “The file name looks normal” | Names like “invoice” or “document” are chosen precisely because they look normal |
| “The automatic scan didn’t flag anything” | Scanning reduces the risk but doesn’t remove it, especially with new or compressed files |
| “I opened it and nothing happened” | Many harmful programs work silently, or activate later |
| “It comes from an address I know” | A compromised contact sends infected attachments without knowing it |
How attachment filters and scans work, and where they stop, is explained in the post on how attachment scanning works. And when the attachment claims to come from your bank, the questions in this post are joined by those about emails pretending to be your bank.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that a single file opened produces impacts on different levels, and on other people too |
| Skills | Being able to read confidentiality, integrity and availability as three concrete questions about any device |
| Secure Behaviour | Checking unexpected senders, keeping up with updates and a disconnected backup |
Reference level: FL2 — Beginner. This is the level at which you move from “I know I shouldn’t open strange attachments” to “I understand what happens if I do.” Awareness of the impacts is what keeps the behaviour steady over time. If you’d like to see where to start on your own path, the digital resilience self-assessment takes just a few minutes.
Summary
- Confidentiality is about what gets copied: saved passwords, sessions, documents, address books.
- Integrity is about what gets changed or controlled: encrypted or altered files, a device under someone else’s control, messages in your name.
- Availability is about what you can no longer use: locked files, an unusable device, a home or office network drawn in.
An infected attachment doesn’t produce just one impact: it opens the door to all three, on the device that opens it and on everything that device can reach.
One thing to do today. Check three things: that your operating system is set to update itself, that file extensions are visible in your folder settings — so you can tell a document from a program — and that a recent copy of your files exists on a drive or service that isn’t permanently connected. It takes about ten minutes, and it covers all three impacts at once.
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- How to recognise phishing that is built to be convincing
- Scareware: the warning that is itself the attack
Related content
- Not opening unknown attachments — the recommendation this expands on
- Consequences of opening a malicious attachment — from technical impacts to concrete effects on work, money, relationships and peace of mind
- Signs of a dangerous attachment — how to spot the file before one of these impacts begins
- What to do after opening a suspicious attachment — the steps to follow, in order of priority
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



