Watch out - those PDFs lurking in your inbox could be a major security risk

 Watch out - those PDFs lurking in your inbox could be a major security risk

Published on April 3, 2025 | Category: tech

Watch out - those PDFs lurking in your inbox could be a major security risk

News
By Sead Fadilpašić published

PDFs are a great launch pad for malicious links, experts warn

Password security
(Image credit: Getty Images)

  • Phishing emails carrying PDF attachments are on the rise, report warns
  • Check Point highlights how hackers love PDFs for customization
  • Social engineering attacks using PDFs are also on the rise

At least one in every five phishing emails carries a .PDF attachment, researchers are saying, warning that the popular file format is being increasingly used in social engineering attacks.

A new report from Check Point Research claims PDF-based attacks now account for 22% of all malicious email attachments, making them particularly concerning for businesses sharing large quantities of these files every day.

In earlier years, many of the attacks relied on JavaScript or other dynamic content being embedded within the files. While this approach is still seen in the wild, it has become less common, since JavaScript-based attacks tend to be “noisy” and easier to detect by security solutions.

Email remains one of the most popular attack vectors out there, with more than two-thirds (68%) of cyberattacks beginning this way.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Today, cybercriminals are pivoting towards a simpler, more effective approach, Check Point says - social engineering.

Generally speaking, the attacks don’t differ much from your usual phishing email. The PDF attachment would serve as a launch pad, often carrying a link that would redirect a person to a malicious landing page or a website hosting malware.

That way, the malicious links are hidden from security filters, making sure the files are received straight to the inbox.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

Furthermore, placing the link in a PDF gives the attackers full control - they can change the text, the image, or any other aspect of the link, making it more trustworthy.

The files are often designed to mimic trusted brands like Amazon, DocuSign, or Acrobat Reader.

“Even though these attacks involve human interaction (the victim must click the link), this is often an advantage for attackers, as sandboxes and automated detection systems struggle with tasks that require human decision-making,” Check Point concluded.

You might also like

  • Private API keys and passwords found in AI training dataset - nearly 12,000 details leaked
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
A sticky note on a laptop reading "password 12345678"

Businesses still haven’t stopped using weak passwords, and it’s getting super risky

Why you should replace your Kaspersky antivirus

Latest
A podcast studio

I tried the latest update to NotebookLM and it’s never been easier to make an AI podcast out of other people’s articles, for better or worse

See more latest
Most Popular
A podcast studio
I tried the latest update to NotebookLM and it’s never been easier to make an AI podcast out of other people’s articles, for better or worse
A sticky note on a laptop reading "password 12345678"
Businesses still haven’t stopped using weak passwords, and it’s getting super risky
Samsung QN90F seen from an angle showing image of soup bowl
Samsung is being weirdly cagey about supporting Netflix's big HDR upgrade that's basically custom-made for its TVs
JetKVM, KVM over IP module
JetKVM is an exciting, tiny open source KVM over IP module that sold almost 100,000 units and it even has a rare RJ11 port
Why you should replace your Kaspersky antivirus
Mario Kart World
The Nintendo Switch 2 will feature DLSS and ray tracing, but we don't know which games support it
Apple Watch Ultra 2 on wrist showing a timer
Apple patents motion-predicting technology that can count reps and identify exercises during a workout
Sergii Figurnyi
Tuta Mail could soon be your default iOS mail app – but only after filing a complaint against Apple
Android phone malware
Dodgy Android smartphones are being preloaded with Triada malware
Start windows 11 button on computer menu screen close up view
Do I really need antivirus for Windows 11?

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More