Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
picture of earth

14 March 2024

3 minutes read time

Phishing 101: Can you get hacked by opening an email?

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

More than three billion phishing emails are sent daily, accounting for over 1% of all email traffic. Every one of us has been sent a malicious email at one time, attempting to lure us into clicking a baited link or downloading an attachment. What happens if you open an email like this? Can simply opening an email be dangerous? 

In this blog, we look at whether it’s possible to get hacked by opening an email.

Can opening an email be dangerous? 

Phishing emails are designed to look like they have been sent from a legitimate organisation, like your bank. Look closer, though, and you’ll see the hallmarks of a scam email intended to elicit personal information or bait you into clicking a link. 

Opening an email like this is relatively harmless as long as you don’t interact with it. Most viruses are triggered by downloading an attachment or clicking a link

If you’ve opened an email you suspect is a phishing attempt, do not: 

  • Download any attachments 
  • Click the links contained in the email 
  • Reply to the email 

Interacting with a phishing email in any way puts your device and your personal information at risk.

What happens if you open a spam email? 

If you open a spam email but don’t interact with it (i.e., download, click, or reply), not much will happen. Most viruses aren’t sophisticated enough to trigger on opening. The worst case is that the scammers will see you’ve opened their email. 

They can then gather information such as your location, IP address, device type, and operating system (e.g., Microsoft, Mac, Android, iOS).  

Cybercriminals use this information to improve their phishing campaigns, with the intention of targeting you again in the future. To be safe, never open an email if it looks suspicious.

If you’re in doubt, don’t open it!  

You’ve opened a suspicious email – what next?

If you’ve opened an email you suspect is part of a phishing scam, do not reply or forward it to anyone else. 

Follow these three steps: 

  1. Mark the email as junk or spam (don’t just delete it). This will help your email provider improve its recognition of phishing attacks
  2. Check your computer for viruses, malware, and ransomware. Then, avoid online shopping or banking until you’re in the clear (your IT department will know how to do this if you don’t). 
  3. Speak to your IT department or IT security consultant. They can ensure no one else in the organisation falls victim to the same scam. 

It only takes one wrong click to land you in hot water, so act promptly and calmly.

How to stop scammers from getting your email address  

Cybercriminals scour the Internet for email addresses of people they can target. They search social media sites, scrape public records, and buy data from unscrupulous sources.  

To protect your credentials, limit how much personal information you share online. We also recommend using a password manager to prevent your passwords from ending up in the wrong hands!

Above all, never share sensitive information with anyone you don’t know or trust.

If you found this post useful, you might also enjoy reading Phishing vs. blagging—what’s the difference?

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more