31/07/2026
If you open an email attachment that looks like an image and it asks you to log in, close it.
There's a phishing trick going around this year that hides inside picture files, and it gets past the filters most businesses rely on.
It uses a file type called SVG. It's an image format, but unlike a normal photo, it can carry code inside it.
Someone double-clicks the attachment expecting a picture. Instead it opens in their browser, runs, and sends them to a fake Microsoft login page built for their exact email.
The email system lets it through because, as far as it can tell, it's just an image.
Researchers flagged a wave of these in early June.
A picture should never send you to a login screen. So if you open an attachment and it asks for your password, don't type it in.
And be careful with any image you weren't expecting, especially one ending in .svg.
People almost never send those on purpose.
Ask your IT provider to block SVG attachments. Hardly any business needs to receive them, so blocking them costs you nothing.