Apparently, the Scammers Still Haven’t Started Writing Emails

Just when I thought the mystery-order-email department might have run out of ideas, two more showed up.


Apparently, writing an actual email is still too much work.


No company introduction. No explanation of what I supposedly purchased. No recognizable merchant. No dollar amount. No useful order details.


Just a mysterious attachment and the digital equivalent of:


“You bought something. Trust me. Open this.”


Yeah, I’ll get right on that.


Mystery Order #1: Thank You for…Whatever I Ordered

The first email arrived with this rather catchy subject line:


“Thank You for Your Order IJAAV~67DSW6N_8H07T29FPNUSVU~7D69Q8CJ520IWP”


Well, that certainly clears things up.


It came from someone named Sarah Black, using a Gmail address.

Inside the email?

Almost nothing.


There's another long collection of letters and numbers and a 36 KB attachment.


That's it.

No store.


No product.

No purchase price.

No credit card information.


No shipping address.


No customer-service information.


Nothing explaining what this alleged order actually is.


To see what I bought, I need to open the attachment.

Nope.


Mystery Order #2 Arrives the Next Day

Then another one arrived.


This time the subject was:


“Your receipt and invoice 2026401GDWNUH are attached”



Now we're getting fancy.


We've upgraded from a mysterious “order” to a mysterious receipt AND invoice.


This one came from someone named Malcolm, also using a Gmail address.

The body of the email contains another random-looking code:

RNUH-H5L1-I0MG2/GM41VL75ZUE

And, naturally, there's another attachment—this one is 24 KB.

Again, the message doesn’t identify a recognizable business.

No explanation of what I purchased.

No price.

No payment information.

No description.

Just an attachment.

🚩 The Attachment Is Still the Email

I've written about this before, and apparently somebody out there wants to provide me with additional examples.

These messages aren't really trying to communicate anything useful.

The attachment is the email.

Everything surrounding it seems designed to create just enough curiosity or concern to make me open it.

Maybe my first reaction is:

What did I order?

Then:

Did somebody use my credit card?

Then:

How much did they charge me?

And finally:

I’d better open this invoice and find out.

That's precisely the reaction I don't want to have.

If I don't recognize a purchase, my first move isn't to open a mystery attachment from an unfamiliar Gmail account.

I'm going directly to my bank, credit-card company, retailer account, or whatever legitimate service supposedly processed the transaction.

Curiosity Can Be the Bait

I haven't opened either attachment, so I don't know what's inside them.

I can't claim they're malware without examining them.

And that's really the point.

I don't need to know what's inside.

Neither message gives me a reason to take that risk.

If I really made a purchase, I can verify it independently.

If there's an unauthorized charge, I can see it through my financial institution.

If a legitimate company needs to contact me about an order, I can go directly to that company's website or app rather than following instructions contained in an unsolicited email.

Opening a mystery file shouldn't cost me to find out whether I supposedly spent money.

Two Emails, Same Basic Formula

These arrived on consecutive days from different Gmail addresses with different names, different order numbers, and different attachments.

But look at the structure:

Unexpected purchase notification → vague message → meaningless-looking number → attachment → curiosity.

That's what catches my attention.

They don't need me to believe the email for very long.


They need me to think:


“What the heck did I buy?”


…and click.

Don't Let the Email Create the Emergency

That's another lesson I've learned from documenting these messages.

A suspicious email shouldn't create a problem and then dictate how I investigate it.

If an email tells me there's an order I don't recognize, I'll check my accounts independently.

If it says there's a PayPal charge, I'll log in to PayPal independently.

If it says there's a credit-card transaction, I'll check that card myself.

If it claims there's an Amazon order, I'll open Amazon myself.

I don't need the mystery attachment.

Be a Good Neighbor

These emails may look ridiculous to someone who's seen hundreds of them.

Not everyone has.

Someone else might see “Thank You for Your Order” and immediately panic.

Maybe they're worried someone stole their credit card.

Maybe they're afraid hundreds of dollars just disappeared from their checking account.

Maybe they can't remember whether they ordered something.

That's when it's worth saying:

Don't open the attachment yet. Let's verify the supposed purchase another way.

Help someone check the real account.

Show them how to inspect the sender.

Explain why an unexpected attachment deserves caution.

Report suspicious messages.

Then delete them.

Because apparently the scammers still haven't started writing emails.


But they certainly haven't stopped sending attachments.

Next
Next

Day 105: “The Power of We” Sounds Great. I’m Still Waiting for the “We.”