What To Do After a Scam

I Downloaded an Attachment From a Suspicious Email

Downloaded — or opened — an attachment you shouldn't have? Work through these steps in order. Most people are fine, but the next hour matters.

By SpamCheck Editorial Team·Updated 2026-07-15·5 min read

Quick answer

Disconnect the device from Wi-Fi and any cables, do not restart or delete anything yet, then run a full scan with your existing antivirus (Windows Security on Windows, or a reputable second-opinion scanner like Malwarebytes Free). If the file was a .zip, .iso, .lnk, .js, .hta, .scr, .exe, or a Microsoft Office document that asked you to 'Enable Content' or 'Enable Macros', assume it was malicious and change your important passwords from a different, known-clean device. If you use the computer for banking or work, or you see anything unusual after the scan, take it to a trusted local repair shop or your IT team — do not keep using it.

Warning signs to look for

  • The attachment was a .zip, .iso, .img, .lnk, .js, .hta, .vbs, .scr, or .exe file
  • It was a Word, Excel, or PowerPoint file that prompted you to click 'Enable Content' or 'Enable Editing'
  • It was a PDF that opened a login page or asked you to 'verify' to view the document
  • Your browser or email client warned you before the download
  • The sender name looked familiar but the email address did not match
  • Your antivirus popped up a warning that you clicked past
  • After opening, your computer slowed down, a black window flashed, or a program you did not recognize appeared

First 10 minutes: contain it

Disconnect from the internet: turn Wi-Fi off and unplug any Ethernet cable. This stops most malware from 'phoning home', downloading more code, or spreading across your home network. Do not shut down or restart the computer yet — some forensic clues are lost on reboot, and some malware is designed to complete installation on the next boot. Do not delete the email or the file — you may need them if you file a report or hand the device to a professional. If the device is a work laptop, stop and call your IT or security team now; they usually prefer to handle the response themselves.

What the file type tells you about the risk

Plain image files (.jpg, .png) and normal PDFs viewed in a modern PDF reader are usually low risk on their own. The higher-risk categories are: executable and script files (.exe, .scr, .hta, .js, .vbs, .lnk, .msi), archives that hide those inside (.zip, .rar, .7z, .iso, .img), and Office documents where you were asked to enable macros or content. If you only previewed the file in your email client's built-in preview and never actually opened it, the risk is lower — but still finish the steps below.

Scan the device

On Windows, open Windows Security → Virus & threat protection → Scan options → Full scan, and let it finish. On a Mac, built-in XProtect runs automatically, but you can add a free on-demand scan with Malwarebytes for Mac. Because a single antivirus can miss things, a good second step on either platform is a scan with a reputable second-opinion tool such as Malwarebytes Free or ESET Online Scanner. Do this before reconnecting to the internet if possible — most scanners let you update their definitions once, then run offline.

Change passwords from a different device

If any password stored in your browser could have been stolen (email, bank, Amazon, PayPal, work accounts), change those passwords from a phone or another computer you trust — not from the machine you are still cleaning. Start with your primary email account, because whoever controls your email can reset almost everything else. Turn on two-factor authentication anywhere you have not already. Do not reuse the old password.

Watch for signs the scan missed something

Over the next few days, watch for: unexpected password reset emails, charges you do not recognize, friends receiving strange messages 'from you', new browser extensions or toolbars, your cursor moving on its own, or the computer being unusually slow or hot when idle. Any of these is a reason to stop using the device for anything sensitive and get professional help.

When to call a professional

Get hands-on help from a local repair shop, Apple Store, Microsoft Store, or your IT team if: the antivirus found something and could not remove it, you use the device for online banking or work, you saw ransom messages or files you cannot open, or you simply are not sure. A one-time cleanup is far cheaper than a drained bank account. Avoid calling any 'tech support' phone number that appears in a pop-up — those are almost always scams themselves.

Report it

In the U.S., report the phishing email to the FTC at reportfraud.ftc.gov and forward the message to reportphishing@apwg.org. If the attachment appeared to come from a real company (your bank, Microsoft, DocuSign), also forward it to that company's abuse address — most publish one on their security page. Reporting does not undo the download, but it helps take down the campaign faster.

How SpamCheck can help

If you are unsure whether the attachment or the email itself was malicious, forward the original message (with the attachment still attached) to check@spamcheck.com. We will look at the sender, the headers, and the file type and reply in plain English with what to do next.

Frequently asked questions

I only previewed the attachment in Gmail / Outlook — did I 'open' it?
The built-in preview in Gmail, Outlook.com, and the Outlook desktop app runs in a sandboxed viewer and does not execute macros or programs. That is much safer than double-clicking the file. Still run a scan if the file type was risky, but you probably did not infect the device.
Should I factory-reset my computer just to be safe?
Usually no. A full scan with two reputable tools clears the large majority of consumer malware. Reserve a factory reset for cases where a scan found something it could not remove, you see clear signs of compromise after cleaning, or a professional recommends it.
The attachment was a .pdf. Am I okay?
Modern PDF readers (recent Adobe Acrobat Reader, Preview on Mac, Chrome/Edge built-in) are hardened, so most malicious PDFs today rely on tricking you into clicking a link inside the PDF rather than exploiting the reader. If you did not click any link or 'sign in' prompt inside the PDF, the risk is low. Make sure your PDF reader and OS are up to date.
It was a work laptop. Should I tell IT?
Yes, immediately, even if nothing looks wrong. Most companies would rather investigate a harmless click than discover a real incident days later. You will not get in trouble for reporting quickly — you might for staying quiet.
Do I need to tell my bank?
Only if you also entered banking credentials, if the attachment was disguised as a bank document, or if you see any unfamiliar activity. If in doubt, call the number on the back of your card — not any number from the email.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides