For all the sophistication attributed to online threats, a great deal of harmful software still arrives by the most ordinary route imaginable: an email with a file attached. The email might look like an invoice, a delivery notice, a receipt, a job application, a document from a colleague or a message from a supplier. The attachment might be a document, a spreadsheet, a compressed folder or something dressed up to look like one. The mechanism does not depend on breaking into anything; it depends on a person opening the file, which is why it works so well and has kept working for so long.
What makes it effective is that the emails are built to feel expected and urgent. A message that appears to be an unpaid invoice, a failed delivery, a document you must review, or a reply in a conversation you are part of, prompts the natural reaction: open the attachment to see what it is. The senders forge familiar names and plausible subjects precisely to bypass suspicion, and in a busy day, opening an attached file is such a reflex that it happens before any thought about whether the message was genuinely expected. Some attachments do their damage on opening; others ask the recipient to enable something - to allow content, to permit editing, to run a feature - and that extra click is the moment the harm is done.
The single most useful habit is to treat any unexpected attachment as suspect until proven otherwise, regardless of who the email appears to be from, because the sender's name is one of the easiest things to fake. If a file arrives that you were not anticipating - even from a known contact - the safe response is to stop before opening it and consider whether it makes sense: were you expecting this document from this person? Does the message read the way that person usually writes? A quick check through a separate, known channel - a phone call, a message on another app, an email you compose fresh rather than a reply - confirms whether a colleague or supplier really sent it, and takes far less time than recovering from what an opened file can do.
Two further rules keep the risk low. First, be especially wary of any attachment that, once opened, asks you to enable, allow or run something to see the content; that request is a common trigger for the harmful part, and the right answer is almost always no. Second, remember that no legitimate invoice, delivery or official message depends on you opening an attachment urgently and without question - urgency pressing you to open a file is itself a warning sign, not a reason to comply. The tools that scan for bad files help, but they are a backstop; the reliable defence is the pause before the click, and the simple rule that an attachment you did not expect is one you do not open until you are sure.