📎 Inbox and attachments

SVG email attachment: what two August analyses change in your inbox

You open your inbox on a Tuesday morning. Among the forty messages that arrived overnight, one announces a voicemail waiting for you. The sender carries your own company's domain name. A small attachment is clipped to the message, an image, SVG format. It takes one second: you click.

Nothing installs. A tab opens in your browser, a page appears, it asks for your credentials. Your computer asked you to authorise nothing, because there was nothing to install. That is the whole subject of the SVG email attachment, whose mechanism and scale two analyses published in August 2026 describe.

An attachment is not always a document. Sometimes it is a file that opens in the browser, and that does not show in a list of messages.

Quick answer: an SVG email attachment is not always a document: it is a file that opens in the browser instead of installing. Two analyses published in August 2026 put figures on the scale. For a business owner, what changes comes down to one thing: the time and attention spent on daily sorting.

SVG email attachment, .htm, .xhtml: what is a file that opens in the browser?

In a mailbox, most attachments are documents: a quote in PDF, a contract in Word, a table in Excel. You open them, you read them, you file them. The file is passive: it waits to be read.

Some formats work differently. SVG is an image format whose content is written as text, and which the browser can display directly. The .htm and .xhtml files are web pages. On a double click they install nothing: they open a tab. No permission window appears, since there is nothing to authorise. That is what the report published on 18 August 2026 by threat analysis vendor ANY.RUN describes, on a phishing kit sold under the name Mirage2FA: those attachments, in .htm, .xhtml or .svg format, run in the browser instead of installing a program, with the .htm format dominant at 629 samples.

For you, the practical difference is this: in a list of messages, a document and a file that opens in the browser look alike. An icon, a name, a size in kilobytes. Nothing visually separates the two families.

What exactly do the two analyses published in August 2026 say?

Two publications, two different scopes, one point in common: the attachment is the entry point, and the browser is the stage.

AnalysisPublicationVolumes observedMechanism described
INKY, security vendor, reported by Infosecurity Magazine 27 August 2026, reported on 28 August 2026 26,589 messages detected across 5,527 organisations, from 1 June to 4 August 2026. Peak on 3 June 2026: 2,432 messages affecting 1,149 organisations. Fake voicemail notifications relying on attachments in SVG format. 95% of the messages present themselves as coming from the recipient's own domain. The attached file is declared with the MIME type text/plain rather than image/svg+xml.
ANY.RUN, threat analysis vendor 18 August 2026 9,426 addresses targeted, 4,532 people potentially compromised, or around 48%. 3,518 organisation domains, activity observed in 94 countries. 2,885 victims in the United States, or 63.7% of the identified victims. Phishing kit sold under the name Mirage2FA. Attachments in .htm, .xhtml or .svg, opened in the browser. 9,332 potential compromise events, including 4,561 session cookie thefts, the file that keeps a session open without asking for the password again.

Two orders of magnitude stand out. The 5,527 organisations recorded by INKY in a little over two months: this is not bespoke work, it is volume. And around 48% of the addresses targeted in the second report result in a potential compromise.

The technical detail, read for what it is. The 27 August analysis records that the attached file is declared with the MIME type text/plain rather than image/svg+xml, and that 19,994 of the 26,589 messages observed, or 75%, carried a Microsoft spam confidence score of 0 or 1. These elements are declarative traits of the mechanism observed, the way those messages present themselves, and not a judgement on any tool. What to take away as a user: what a file announces about itself is not what it contains.

Why can a message look as if it comes from your own company?

It is the most counter-intuitive figure in the first analysis: 95% of the messages present themselves as coming from the recipient's own domain. In other words, the sender field displays your own domain name.

This is not a feat. The display name and the visible address are pieces of information declared inside the message, exactly like a sender name written by hand on an envelope. You can write what you like on the back of an envelope: it does not change where it was posted.

The consequence is practical. The reflex "it is internal, so it is fine", which saves you time all day long, stops being a reliable sorting criterion. Neither dramatic nor new: simply a habit to file away with the other shortcuts we mistake for certainties.

What does this change in your inbox routine?

Nothing spectacular, and that is exactly the point. What these two analyses move is not your level of equipment: it is how your attention is distributed. A professional inbox is largely handled on autopilot, in blocks of a few seconds per message. That processing mode is what lets you absorb a whole day's volume. It is also what makes a click on an attachment completely painless.

Three questions are enough, and they take one second, before the click:

  1. Was I expecting this message? A notification, an invoice, a shared file: most of our attachments are expected. The ones that are not form a much smaller population, and therefore a much easier one to look at closely.
  2. Does the file match what the message announces? A voice message arriving as an image, a delivery notice as a web page: the gap between the announcement and the format is visible without any technical skill.
  3. What am I being asked to do next? A document is read. A page that asks for your credentials asks you to act. Those are two different kinds of file.

Those three questions cost almost nothing, on one condition: that your inbox is not already saturated. This is where the subject meets that of the time genuinely wasted on email every day. An inbox with 300 unread messages leaves no room for the second of attention. A well-kept inbox does.

Should you therefore be wary of every attachment?

No, and that would be the worst lesson to draw from these figures. The overwhelming majority of attachments arriving in a small business are working documents: quotes, invoices, contracts, spreadsheets, minutes. They carry the information you need in order to reply, and opening them is part of the job.

That is precisely the role we give attachments in Neston. The assistant reads office documents, PDF, Word and Excel, to draw out the context useful for drafting a reply, in new Outlook, classic Outlook and Outlook on the web. It learns your style from around 300 sent and 500 received emails, builds a profile per correspondent, files automatically, detects deadlines and proposes a reply in about four seconds. You read it, you approve it, you send it.

Let us be plain: Neston is not a security tool. It detects nothing, filters nothing, protects against nothing. It works on time and context, not on threat. What it changes is the volume of attention spent on the mechanical part of your inbox, and therefore what you have left for the messages that deserve a look. The general framework is set out in our method for piloting your inbox rather than being run by it.

An attachment remains, in the vast majority of cases, a document to read. The two August analyses simply serve as a reminder that the exception exists, and that it does not look like anything in particular.

Neston is in early access.

The assistant plugs into Outlook, learns your style from your emails, reads your office attachments and prepares a reply that you read and approve before it is sent. Early access is free, on a waiting list.

Join the waiting list →

Windows 10/11 · Outlook · Optional Mistral EU

Further reading

FAQ: attachments, browser and sender

Why can an attachment reach my inbox without being flagged?
Because a file declares what it is. In the campaign analysed by INKY and reported on 28 August 2026, the attached file was declared with the MIME type text/plain rather than image/svg+xml. A mail application displays what is declared to it. The practical consequence fits in one sentence: the look of an attachment in a message list does not tell you what it contains, and it is the context of the message that informs you.
What is a file that runs in the browser, in plain language?
It is a file that, when double-clicked, installs nothing on your computer but opens a page in your browser. The formats recorded in the ANY.RUN report of 18 August 2026 are .htm, .xhtml and .svg, with .htm dominant at 629 samples. You see no installation and no permission prompt: only a tab that opens. That is what makes the gesture completely ordinary, and why it deserves one second of attention.
Can an email that looks like it comes from my own company not come from it?
Yes. In the campaign published on 27 August 2026, 95% of the messages presented themselves as coming from the recipient's own domain. The display name and the visible domain are pieces of information declared inside the message, in the same way as a sender name written on an envelope. Seeing your own domain name in the sender field is therefore not, on its own, a confirmation of origin. Content and context matter more.
A note on reading this. The figures quoted come exclusively from the two publications listed in the sources, in their state at their date of publication. They describe observations made by their authors over a given period, and constitute neither an exhaustive measurement nor a projection. No organisation concerned is named or identifiable. This article describes a mechanism from the point of view of a daily inbox routine: it does not constitute technical advice and does not replace the support of a professional.
YB
Yvan Bosser
Founder of Neston · Ex-founder of Comptasanté (IK Partners exit 2023)
Yvan designs Neston, the AI email assistant integrated with Outlook, based on his own experience as an executive. Contact: yvan@neston.fr · LinkedIn.

🔬 Sources

Published 1 September 2026 · Reading time: 5 minutes · approx. 1,986 words