Attachments are the most common delivery route for malware.
BEFORE OPENING ANYTHING
Were you expecting it? Does the sender normally send this kind of file? Does the file type make sense for what it claims to be?
FILE TYPES TO TREAT WITH SUSPICION
.exe, .scr, .bat, .cmd, .js, .vbs: executable, and almost never legitimate as email attachments .zip and .rar: sometimes used to hide the above from filters Office documents prompting you to enable macros or enable editing to see content .html attachments, which often contain fake login pages PDFs from unknown senders, which can carry links to phishing pages
IF IN DOUBT
Phone the sender using a number you already have. A colleague's account may be compromised even though the message looks genuine.
SENDING ATTACHMENTS
Large files bounce. Use a file-sharing link for anything over a few megabytes. Do not send sensitive documents unencrypted. Email is not private in transit unless both ends support encryption.
YOUR OWN PROTECTION
Keep devices patched, run antivirus, and keep backups. Ransomware usually arrives by email.