This article published in Forbes addresses the risks posed by suspicious email attachments. It highlights the five file types attached to the majority of malicious emails and gives tips on how to identify them by file extension.
Which email attachments are most risky?
Based on analysis from security provider F-Secure, about 85% of all malicious emails carry one of just five attachment types:
- .DOC – typically Microsoft Word files
- .XLS – typically Microsoft Excel files
- .PDF – usually opened with Adobe Reader or similar tools
- .ZIP – compressed archive format, often used to bundle multiple files
- .7Z – another compressed archive format, similar to ZIP
These formats are common in everyday business, which is exactly why attackers use them. They blend into normal workflows and don’t immediately look suspicious.
As a practical rule, any unexpected .DOC, .XLS, .PDF, .ZIP, or .7Z attachment should trigger extra caution. Before opening, verify who sent it, why they sent it, and whether you were expecting that specific file.
How big is the email threat problem, really?
Even a modest click rate becomes a serious business risk when you look at the volume of email moving around the world.
F-Secure’s research found that the “click rate” for malicious attachments is around 13.4%, and has recently climbed to about 14.2%. That means roughly 1 in 7 people who receive a malicious attachment end up opening it.
Now put that next to global email traffic:
- ~52.9 billion legitimate emails are sent daily (Cisco Talos estimate).
- ~307 billion spam emails are sent daily — nearly six times the volume of legitimate email.
Not all spam is malicious, but with that scale, even a 14% click rate on the malicious portion can translate into a steady stream of successful attacks. For a business, that means:
- Higher risk of ransomware incidents
- Potential cryptomining malware quietly consuming resources
- Increased exposure of sensitive data and systems
This is why many organizations are reimagining email security as a shared responsibility between technology (filters, scanners) and people (awareness, training).
How can employees quickly spot a suspicious attachment?
You don’t need to be a security expert to reduce risk. A short checklist can help employees pause before they click:
- Look at the file type first
If it’s .DOC, .XLS, .PDF, .ZIP, or .7Z, treat it as higher risk, especially if you weren’t expecting it.
- Verify the sender details
Check whether the email address matches the display name (for example, does bob.smith123@example.com reasonably match “Bob Smith”?) and whether this is someone you normally work with.
- Read the subject and message carefully
Ask:
- Does this sound like how this person or organization usually writes?
- Is the tone, grammar, or urgency unusual?
- Is there unexpected pressure to “open this now” or “act immediately”?
- Confirm out-of-band if unsure
If anything feels off, contact the sender through another channel (e.g., phone, chat, or a new email you initiate) to confirm they actually sent the file.
Taking just a few extra seconds to run through these steps can help your organization rethink everyday email habits and significantly lower the chance of a ransomware or cryptomining malware incident starting with a single click.