All systems operational · Ormskirk, North West England

Beware of That Corrupted Email Attachment

Cyber criminals are sending deliberately corrupted Word documents that bypass email security filters. When opened, Word repairs the file to reveal a phishing link inside. Here is what your team needs to know.

A Technique Designed to Bypass Security Filters

Email security filters are good at blocking known malicious files. Cyber criminals have responded by sending deliberately corrupted files instead. A corrupted Word document arrives in your inbox, and when you open it, Microsoft Word automatically attempts a repair. The document then appears entirely normal, with nothing to suggest anything is wrong.

Inside the repaired document is a malicious QR code or link leading to a fake Microsoft 365 login page. Enter your credentials there and the attacker has everything they need to access your account, your files, and potentially your entire business network.

Why It Is Effective

The technique works because the file arrives in a corrupted state that security scanners struggle to analyse. By the time Word has repaired it and the content is visible, the security check has already passed. The login page the link leads to is a convincing replica of a genuine Microsoft page, with no obvious signs of fraud.

Attackers only need one employee to enter their details. A single compromised account gives access to cloud systems, email contacts, shared files, and potentially the ability to send further phishing messages to colleagues and clients from a trusted address.

How to Protect Your Business

Pause before opening unexpected attachments

Urgency is a core part of these attacks. Emails requesting immediate action, claiming a payment is due, or suggesting a document needs urgent review are designed to bypass careful thinking. Taking a moment to question whether you were expecting this document, and from this sender, is enough to catch many attacks.

Verify through a different channel

If an email looks suspicious, contact the sender directly by phone or a separate message to confirm they sent it. Do not reply to the original email, as the sender address may be spoofed. This is particularly important for any email requesting login credentials or containing a QR code.

Enable multi-factor authentication

Even if an employee’s credentials are stolen via a phishing page, MFA prevents the attacker from using them to log in without the second factor. It does not stop the credentials being taken, but it does stop them being used.

Train your team on current techniques

Most staff will not have encountered this specific attack before. Sharing awareness of how corrupted attachment phishing works, and what to look for, gives your team the context to treat unexpected Word documents with appropriate caution.

Support Across the North West

Blowfish Technology provides email security, MFA deployment, and cyber awareness training across the North West, including IT Support Manchester, IT Support Liverpool, IT Support Chester, IT Support Ormskirk, IT Support Southport, and IT Support Preston.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.