PanicStation.org
us Technology & digital loss

What to do if…
you opened a suspicious email attachment and fear it installed malware

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Disconnect the affected device from the internet and stop using it for passwords, banking, shopping, or other sensitive activity. Use a different trusted device to protect your accounts and get help checking the affected device.

Do not do these things

  • Do not reopen the attachment to investigate it.
  • Do not enter passwords, payment details, or personal information on the affected device.
  • Do not call numbers or follow instructions shown in the email, attachment, pop-up, or unexpected security warning.
  • Do not install cleanup software from an advertisement, pop-up, unsolicited message, or unfamiliar website.
  • Do not pay a ransom or send money because of an on-screen demand.
  • Do not forward the attachment to another person.
  • Do not erase, reset, or reinstall an employer, school, or organization-managed device unless its IT team tells you to.
  • Do not assume that a pop-up claiming to find malware is genuine.

What to do now

  1. Disconnect the affected device. Turn off Wi-Fi, unplug any Ethernet cable, and disconnect any external storage devices that were not already attached.

  2. Stop using the device for email, financial accounts, shopping, work systems, password changes, or anything else involving sensitive information.

  3. Write down the email sender, subject line, attachment name, when you opened it, and what happened next. Note whether you enabled content, approved a warning, entered a password, ran a command, or installed anything.

  4. If the device belongs to an employer, school, or other organization, contact its IT or security team from another device. Follow its instructions before deleting the message, running security tools, shutting down the device, or reconnecting it.

  5. If it is your personal device, start with security software that was already installed or built into the device. Run a full scan if it can scan while the device is offline. If it needs an update, cannot run, or reports a threat you cannot remove, keep the device disconnected and use another device to find the manufacturer’s official support or a technician you already know and trust.

  6. From a different trusted device, change passwords for accounts you used after opening the attachment or whose passwords may have been stored on the affected device. Begin with your primary email, password manager, financial accounts, and work accounts. Replace reused passwords and enable multi-factor authentication where available.

  7. Check important accounts for unfamiliar sign-ins, sent messages, purchases, transfers, password changes, or changes to recovery email addresses and phone numbers. Contact the provider or financial institution through its official app, website, statement, or a number you already know is genuine if you find anything unfamiliar.

  8. Use your email provider’s phishing or junk-reporting control. Report fraud or attempted fraud to the Federal Trade Commission. Use IdentityTheft.gov if personal information was misused, and consider reporting cyber-enabled crime or financial loss to the FBI’s Internet Crime Complaint Center.

What can wait

You do not need to identify the exact malware, confront the sender, buy new security software, replace the device, or decide whether to erase it right now. Containing the possible infection, protecting important accounts, and getting a trustworthy assessment come first.

Important reassurance

A suspicious attachment may or may not have installed malware, and opening it alone does not establish what happened. Disconnecting the device and protecting your accounts are useful precautions while the situation is checked.

Scope note

This guide covers immediate containment and account-protection steps only. Removing an infection, restoring data, investigating possible exposure, or responding to financial loss may require specialist help.

Important note

This is general digital-safety information, not professional cybersecurity, legal, financial, or law-enforcement advice. Advice for a managed device should come from the organization responsible for it.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us