It turns out that halfway clever phishing attacks really, really work

the bottom line is never open an attachment unless you were waiting for it to arrive
J