More than three billion phishing emails are sent daily, accounting for over 1% of all email traffic. Every one of us has been sent a malicious email at one time, attempting to lure us into clicking a baited link or downloading an attachment. What happens if you open an email like this? Can simply opening an email be dangerous?
In this blog, we look at whether itâs possible to get hacked by opening an email.
Can opening an email be dangerous?
Phishing emails are designed to look like they have been sent from a legitimate organisation, like your bank. Look closer, though, and youâll see the hallmarks of a scam email intended to elicit personal information or bait you into clicking a link.
Opening an email like this is relatively harmless as long as you donât interact with it. Most viruses are triggered by downloading an attachment or clicking a link.
If youâve opened an email you suspect is a phishing attempt, do not:
- Download any attachments
- Click the links contained in the email
- Reply to the email
Interacting with a phishing email in any way puts your device and your personal information at risk.
What happens if you open a spam email?
If you open a spam email but donât interact with it (i.e., download, click, or reply), not much will happen. Most viruses arenât sophisticated enough to trigger on opening. The worst case is that the scammers will see youâve opened their email.
They can then gather information such as your location, IP address, device type, and operating system (e.g., Microsoft, Mac, Android, iOS).
Cybercriminals use this information to improve their phishing campaigns, with the intention of targeting you again in the future. To be safe, never open an email if it looks suspicious.
If youâre in doubt, donât open it!
Youâve opened a suspicious email â what next?
If youâve opened an email you suspect is part of a phishing scam, do not reply or forward it to anyone else.
Follow these three steps:
- Mark the email as junk or spam (donât just delete it). This will help your email provider improve its recognition of phishing attacks.
- Check your computer for viruses, malware, and ransomware. Then, avoid online shopping or banking until youâre in the clear (your IT department will know how to do this if you donât).
- Speak to your IT department or IT security consultant. They can ensure no one else in the organisation falls victim to the same scam.
It only takes one wrong click to land you in hot water, so act promptly and calmly.
How to stop scammers from getting your email address
Cybercriminals scour the Internet for email addresses of people they can target. They search social media sites, scrape public records, and buy data from unscrupulous sources.
To protect your credentials, limit how much personal information you share online. We also recommend using a password manager to prevent your passwords from ending up in the wrong hands!
Above all, never share sensitive information with anyone you donât know or trust.
If you found this post useful, you might also enjoy reading Phishing vs. blaggingâwhat’s the difference?





