What to do now
Suspicious email attachment: check the file before you open it
Last checked
On this page
Do this now
Already opened it? Disconnect and scan
On a work device, call your IT team first and follow their instructions. On your own device: disconnect it from the internet, run a full antivirus scan and change your passwords from another device.Otherwise, leave it closed
Don’t open it, and don’t forward it to someone else to open.Ask the sender another way
Call or message them using a number or address you already had, not the one in the email. If they sent nothing, report the email, then delete it.Look at what the file really is
Programs and scripts (.exe, .js, .vbs, .bat, .scr), shortcuts (.lnk) and disk images (.iso) are not documents: Outlook blocks them as attachments because they can carry viruses. In a .zip archive, they still get through. A name such as invoice.pdf.exe is a program, not a PDF.Never enable content or macros to read it
If a document opens with a banner asking you to enable content or macros, close it: enabling them is what lets its code run.For a second opinion, check its hash
Save the file without opening it and compute its SHA-256 withGet-FileHashin PowerShell on Windows,shasum -a 256in Terminal on a Mac, orsha256sumon Linux, followed by the file’s path. Paste the result into the file hash lookup below.Report the email
Send it to the services below, then delete it.
On this page07
Check it with isMalicious
isMalicious compares what you paste with the threat intelligence sources it collects. It does not scan your device and cannot undo what already happened.
File hash lookup
Paste the file’s SHA-256, SHA-1 or MD5 into the file hash lookup. Only the hash leaves your device: isMalicious does not receive, open or run the file. A match means a threat source lists this exact file.
- What it does not mean
- No match is common for new or targeted malware, and changing a single byte of a file changes its hash. A file that NIST’s software reference library knows is identified as published software, which says what it is, not that it is harmless.
- Malware file hash database: the malware samples with enough threat intelligence for a report.
Report it
Keep the message, the link or the number until you have reported it: you will need them. These are the services that handle each case.
In the United States
FTC, ReportFraud.ftc.gov (opens in a new tab)
Report the scam to the Federal Trade Commission, whether or not you lost money.
Anti-Phishing Working Group
The address the FTC gives for forwarding phishing emails.
In the United Kingdom
Report Fraud (opens in a new tab)
If you lost money or were hacked, in England, Wales or Northern Ireland: report online or by phone. It replaced Action Fraud in December 2025.
Police Scotland (opens in a new tab)
In Scotland, report fraud and cyber crime to Police Scotland.
NCSC Suspicious Email Reporting Service
Forward the suspicious email. The NCSC analyses it and the sites it links to.
Somewhere else? Report to your national police or your country’s cybercrime reporting service.
In France? The French version of this guide lists the French services.
How to spot the next one
- You weren’t expecting it, even if it comes from someone you know: their account may have been hacked.
- You expected a document and received an archive (.zip) or a disk image (.iso).
- The document says it can only be displayed once you enable content or macros.
- The file name has two extensions, such as invoice.pdf.exe.
Questions
Does isMalicious scan the file?
No. The file hash lookup checks the file’s hash against threat listings; it does not upload or run the file the way a malware sandbox does.
How do I get a file’s SHA-256?
On Windows, open PowerShell and run Get-FileHash followed by the path to the file: SHA-256 is its default. On a Mac, run shasum -a 256 followed by the path in Terminal. On Linux, run sha256sum followed by the path.
The hash is not listed. Can I open the file?
Not on that basis alone: new or targeted malware is often unlisted. Open it once the sender has confirmed they sent it, and never enable content or macros.
I opened it on a work computer. Should I tell IT even if nothing happened?
Yes, straight away. Tell them what you opened and when: the UK’s NCSC asks anyone in that situation to contact their IT department immediately.
Related guides
Close the page, then deal with what you typed, downloaded or allowed after the click.
Call the supplier on a number you already had before paying any new bank details.
Don’t call the number: close the page, and if you already called, cut the remote access.
Sources
The steps follow these official pages, read on :
- MicrosoftBlocked attachments in Outlook (opens in a new tab)
- MicrosoftMacros from the internet are blocked by default in Office (opens in a new tab)
- MicrosoftGet-FileHash (opens in a new tab)
- NCSCPhishing scams: if you’ve shared sensitive information (opens in a new tab)
- FTCMalware: How To Protect Against, Detect, and Remove It (opens in a new tab)
- Cybermalveillance.
gouv. frPiratage d’un système informatique de particulier, que faire ? (opens in a new tab) (in French)
Free account
Keep checking with a free account
Without an account, checks stop at 10 an hour. With a free account you skip that wait and can run up to 60 a minute, and you can save up to 10 reports every 30 days.
No credit card required