
Workplace MODULE
Suspicious attachments
The file name is a claim. Learn what actually opens.
What really happens when you open a file, which attachment types are carrying attacks in 2026 rather than the macro era everybody still teaches, and how to find out whether a file is safe without opening it to see. For everybody in an organisation, with no technical background assumed.
- Explain why a file name, an icon and a familiar sender prove nothing about a file.
- Recognise the attachment types doing the damage in 2026, including the ones that look harmless.
- Check, or report, an unexpected attachment without ever opening it.
Your learning path
01What opening a file actually doesUnderstand what happens when you open a file, and why its name and icon are not evidence of anything.Locked02The formats that matter nowRecognise the attachment types actually being used in 2026, and why the advice about macros is out of date.Locked03Archives, and the password that protects nobodyUnderstand why so much arrives inside an archive, and what a password on it really does.Locked04Shortcuts, scripts and files that are instructionsRecognise the file types whose only purpose is to make something happen.Locked05But it came from someone I knowUnderstand why a familiar sender is the weakest reassurance available, and what to check instead.Locked06What to do instead of opening itHandle an unexpected attachment confidently, and act quickly if you have already opened one.LockedPut your decisions into practice.
Complete each lesson’s scenario, then take eight new questions. A score of at least 80% earns a personal completion record. Retry with feedback; this is a learning exercise, not a timed exam or professional accreditation.
Lessons and scenarios are original Jatzo material informed by published guidance and research:
- Microsoft Security: email threat landscape, second quarter 2026
- Microsoft Security: email threat landscape, first quarter 2026
- Barracuda: 2026 email threats report
- HP Wolf Security: threat insights report, March 2026
- AhnLab ASEC: phishing email trends report, April 2026
- INKY at Kaseya: SVG smuggling in a voicemail phishing campaign
- Forcepoint X-Labs: Phorpiex shortcut phishing and Global Group ransomware
- Microsoft: macros from the internet are blocked by default in Office
- Microsoft: blocked attachments in Outlook
- NCSC: report a suspicious email
- Report Fraud: reporting a fraud
