I received a suspicious email at my business address with the subject "ACH payment." The sender's address and claimed company seemed questionable, and someone was copied who did not appear to work for that company. I expected a PDF attachment, but it was actually an HTML file. I downloaded and opened it, then closed the browser immediately without allowing the page to finish loading. I deleted the file and emptied the trash, and the email later disappeared from my inbox. I use an authenticator app for email sign-in. Could opening the HTML attachment have installed malware, exposed my information, or compromised my email? Could an attacker bypass multi-factor authentication if the file captured anything?
2 Answers
Report the message to your company’s IT or security team, especially because it went to a business account. They can check mail logs, endpoint security alerts, and whether the attachment was delivered to anyone else. Also make sure you did not install anything, grant browser permissions, or open a downloaded file after the first attempt. Multi-factor authentication generally helps a lot, but phishing pages can still steal an active session or trick someone into approving a sign-in, so review recent login locations and revoke unfamiliar sessions.
Opening an HTML attachment can be risky because it may redirect to a fake login page or exploit a browser vulnerability, but simply opening it does not automatically mean your Mac or email was compromised. Since you closed it quickly and did not enter credentials or approve an authentication request, the risk is lower. Still, update macOS and your browser, run a reputable security scan, check browser downloads and extensions, and review your email account’s recent sign-ins and active sessions. If you entered a password anywhere, change it from a trusted device and revoke existing sessions.

I did not enter any credentials or approve an authenticator request. I’ll update everything and check the account activity.