An “invoice” you do not remember receiving. A compressed archive labelled “requested documents”. A chat message from a number you do not recognise: “here are the photos from last night”. Attachments arrive every day, by email and by message, and almost all of them are harmless. Opening them is an automatic gesture, often done in a hurry, in between other things.
Precisely because it is automatic, that gesture is also one of the simplest ways for a harmful program to get into a computer or a phone. Whoever prepares these messages does not need to force anything: all they need is for someone, out of curiosity or conscientiousness, to double-click. It does not happen because the person opening the file is careless or unprepared. It happens because the attachment is designed to look normal, and because most attachments really are.
This recommendation — R17 of the Cyber Welfare Framework — proposes a simple habit: an attachment you were not expecting stays closed until you know who sent it and why. Not opening unknown attachments does not require technical skills or special tools. It requires a short pause, and knowing what to do during that pause.
What this recommendation says
Recommendation R17 states that an unexpected attachment is not opened until you have checked who sent it and for what reason. An attachment is a file added to a message: a document, an image, an archive, a program.
In practice, it means four things:
- stopping in front of any file you did not ask for or were not expecting;
- asking yourself who is sending it and why, looking at the context and not just at the sender’s name;
- checking through a different channel: a phone call to a number you already know, or a new message written by you, not a reply to the one you received;
- when in doubt, deleting the message without opening the file.
It also applies when the sender is someone you know. An email or chat account can be compromised, meaning it ends up under someone else’s control, and that person uses it to send attachments to the whole address book. The name is right, the profile picture too: the only thing that has changed is who is actually writing. This is covered by the recommendation on messages sent in your name, seen from the side of the person whose account is being used by others.
What it is not. It is not an invitation to be suspicious of every file or to stop using attachments: work, school, family life and paperwork are full of them, and rightly so. Nor does it ask you to analyse a file to work out whether it is dangerous: that is a job for specialised tools, not for people. The rule is simpler than that: you do not have to guess whether an attachment is safe, you only need to know where it comes from before you open it.
Where it applies. To email attachments, to files received in messaging apps and group chats, to those sent in private messages on a social network, and to links that lead you to download a file shared online. It covers the home computer, your phone, your tablet and your work devices.
Why it matters
An attachment can contain malware, meaning malicious software designed to do something without your consent. Opening the file is often the only step it needs to get going.
What happens next depends on the type of program, but the most common outcomes are few and recurring:
- information theft — saved passwords, documents, photos, payment details, conversations;
- control of the device — someone watches what you do or uses your computer for other purposes;
- locked files — in the case of ransomware, a type of malware that makes your files unreadable and demands a ransom to give them back;
- spreading to your contacts — your account is used to send the same attachment to friends, colleagues and clients.
The files most often used to deceive are few and recognisable: documents that ask you to “enable content”, compressed archives (sometimes protected by a password written in the message itself), files with one extension hidden behind another, such as invoice.pdf.exe, and shortcuts that look like documents but launch a program. The extension is the last part of a file name, after the dot, and it tells you what kind of file it is. There is no need to learn them by heart: the rule about where a file comes from applies to all of them.
There is one more aspect that makes the rule even more useful: many attacks exploit flaws that manufacturers have already fixed. Keeping your software up to date closes quite a few of those doors, so a malicious attachment opened by mistake has less room to act. Updates and caution work together; neither of them, on its own, is always enough.
| Benefit of the rule | Why it counts |
|---|---|
| Stops the attack at the first step | A file that stays closed, in most cases, cannot do anything |
| Requires no technical skills | All it takes is asking who sent it and why, and checking |
| Protects your contacts too | A device that is not infected does not spread attachments in your name |
| Works even against perfect fakes | You do not need to recognise the harmful file, only its origin |
| Reduces anxiety and haste | A fixed rule replaces judgements made in a rush |
A concrete example
It is Thursday afternoon. An email arrives from an address that looks like a courier’s: “Delivery failed. Please find attached the form to rearrange it.” You are in fact waiting for a parcel, so the message seems to make sense. The attachment is a compressed archive.
At this point the rule only asks you to pause for a moment. Who is sending it? A courier different from the one named in your order confirmation. Why? For a form that is not usually needed: deliveries are managed from the website or app of the shop you bought from. Instead of opening the file, you open the shop’s website yourself, from your bookmark or by typing the address, and check the status of the delivery. The parcel is on its way, with no problems reported. You delete the email.
The next day, a chat message arrives from a friend: “Look at this great document!”, with a file attached. It is her name, her photo. But she never writes like that, and she has never sent you documents before. You call her: she knows nothing about it, and her account was compromised the evening before. Thanks to your call, she realises before the message reaches everyone.
In both cases, you did not have to work out what was inside the file. It was enough to ask who and why, and to check somewhere else.
When to apply it
The rule always applies, but there are situations where it makes an obvious difference.
- Invoices, bills and receipts you are not expecting. They are among the most common pretexts, because they involve money and prompt you to check straight away.
- Shipping and delivery notices. Especially during periods of frequent online shopping, when there is almost always a parcel on its way.
- Messages that mention your bank or a payment service. Here the rule adds to the one on emails pretending to be your bank: no attachments, no links, check through the official channel.
- Known contacts writing in an unusual tone. A colleague writing in a rush, a relative sending “an important document” without explaining what it is.
- Group chats and forwarded messages. A file that travels from group to group has lost its origin: nobody knows any more who created it.
- At work. CVs, quotes, orders, payment reminders: work inboxes receive many attachments from strangers, and they are a frequent target.
- Deadlines and official notices. Messages that appear to come from public bodies, courts or the tax authorities, often in an urgent tone.
How to apply it
You do not need a complicated procedure. What you need is a short sequence, always the same.
- Stop before opening. Ask yourself: was I expecting this file? If the answer is no, or if you are not sure, do not open it yet.
- Look at who is writing and what they are asking. The display name can be chosen freely: check the full address and ask yourself whether the message makes sense coming from that person or that company. Be wary of requests to hurry.
- Check through a different channel. Call a number you already know, or write a new message to the person, without replying to the one you received. For companies and services, go to the official website or app on your own and check there.
- When in doubt, delete without opening. If the attachment really was important, whoever sent it will get it to you again. A genuine document can wait for a check; a fake one is only waiting for a click.
- Do not enable content, macros or editing. A macro is a small program embedded in a document. If a file you have just opened asks you to enable something in order to “view the content”, close it.
- Keep your device’s protections turned on. Automatic updates, the operating system’s built-in protection and your email filters should all be active. They do not replace the rule, but they limit the damage if something slips through.
- Report instead of forwarding. Use the option to report unwanted or suspicious mail; at work, let whoever looks after IT know. If the attachment came from a known contact, warn them through another channel: they may not know their account has been compromised.
Common mistakes to avoid
- Trusting the sender’s name. The display name is the easiest part to fake, and a compromised account shows the real name of a real person.
- Opening it “just to see what it is”. That is exactly the gesture the attachment is waiting for. Curiosity is human; checking takes a minute.
- Replying to the message to ask whether it is genuine. If the account is compromised or the sender is fake, the reply will come from whoever sent the attachment, reassuring you that everything is fine.
- Forwarding the file to someone for an opinion. This moves the risk onto another person instead of removing it.
- Trusting the icon. The icon of a PDF or a photo does not guarantee that the file really is a PDF or a photo.
- Assuming your device’s protection is enough. Filters stop a great deal, but not everything: new attacks can get through before they are recognised.
- Treating a file as safe because it arrived in a chat rather than by email. The channel changes; the mechanism stays the same.
How this connects to the Cyber Welfare Framework
R17 turns an everyday gesture, opening a file, into a conscious choice: it is one of the basic behaviours that make security a habit rather than a worry.
| Pillar | How this contributes |
|---|---|
| Skills | Knowing how to verify a sender through a different channel and recognising requests to enable content |
| Awareness | Understanding that even a known contact can send a harmful attachment without realising it |
| Secure Behaviour | Never opening an unexpected attachment before being clear about who sent it and why |
Digital maturity levels.
- FL1 — Basic. You open attachments as soon as they arrive, especially if the sender looks familiar. It is the most common starting point, not a fault.
- FL2 — Beginner. You stop in front of unexpected attachments and, when in doubt, delete them or ask the sender for confirmation through another channel.
- FL3 — Autonomous. You routinely check where files come from, keep your devices up to date and never enable content or macros in documents you receive.
- FL4 — Skilled. You recognise recurring pretexts, report suspicious messages and know what to do if a file is opened by mistake.
- FL5 — Expert-Guide. You help family, colleagues and your organisation adopt the same rule, and talk about it without embarrassment when something goes wrong.
R17 is the key step from FL1 to FL2, and it remains an active requirement at every level after that.
How to check you are applying it properly
Three questions, to be answered honestly.
- The last time I received an attachment I was not expecting, did I stop before opening it?
- If a friend sent me a file with a strange message, would I know how to check it without replying to that message?
- Have I ever enabled content or macros in a document I received, without knowing what they were for?
Quick checklist
- ☐ I do not open attachments I was not expecting without first understanding who sent them and why
- ☐ I check with the sender through a different channel, not by replying to the message I received
- ☐ When in doubt, I delete the message without opening the file
- ☐ I apply the same rule to email, chats, group chats and private messages
- ☐ I never enable content or macros in a document I have received
- ☐ Automatic updates and system protection are turned on on my devices
If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.
In short
Opening an attachment is a quick gesture, and it is precisely that speed that gets exploited. A harmful file can steal information, lock documents or use your account to reach other people, and it can arrive even from a contact you know.
The rule does not ask you to become a file expert: an unexpected attachment stays closed until you know who sent it and why. You check through a different channel, you do not enable content, you keep your devices up to date and, when in doubt, you delete it.
Security, here, is not distrust of other people. It is the freedom of not having to guess: you know what to do every time, and you do it calmly.
Something to think about. How many of the attachments you opened in the last month were you actually expecting?
Explore this recommendation
This recommendation is the pivot of a content unit. Each post looks at a different aspect.
- Impact of infected attachments — what gets hit, in terms of the confidentiality, accuracy and availability of your data and devices
- Consequences of opening a malicious attachment — the concrete effects on the operational, financial, legal, reputational and personal levels
- What to do after opening a suspicious attachment — the mitigations, in order of priority
- Signs of a dangerous attachment — the indicators to look for before and after opening, and what they mean
- How attachment scanning works — the checking tools available, their advantages and limits
- Malware in email attachments — how the attacks that travel inside a file are built
Related resources
Short reads from the Resources section, for anyone who wants to focus on a single aspect:
- How to Recognise Phishing When It Is Built to Be Convincing
- Scareware: The Warning That Is Itself the Attack
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



