Apparently, the Scammers Have Stopped Writing Emails
I've written quite a bit lately about scam emails, suspicious recruiters, mystery attachments, and people desperately trying to convince me to click something.
Apparently, we've now reached the minimalist phase of scamming.
Why bother writing an elaborate fake invoice when you can simply send me an attachment and hope I do the rest?
Over the past few days, I received two more emails that follow essentially the same strategy: almost no information, a mystery attachment, and curiosity as the bait.
🚩 Scam Email #1: Thank You for the Order!
The first one came from someone identifying himself as Philip Smith, using a Gmail address.
The subject:
“Re: Thank you for the order 8WXJBZYM91JW858X2A”
Oh!
Thank you for my order!
There's just one tiny problem.
What order?
There's no company name.
No product.
No price.
No shipping information.
No recognizable merchant.
The body of the email contains essentially nothing except the same mysterious string:
8WXJBZYM91JW858X2A
And then there's an attachment.
A 244.4 KB file with a filename beginning with a date and my name.
That's a nice touch.
Putting someone's name in a filename can make the attachment feel personalized and legitimate.
But I'm supposed to believe I placed an order somewhere, received no explanation of what I purchased, and now need to open an unexplained attachment to discover what happened?
No thanks.
🚩 Scam Email #2: They Didn't Even Bother With a Subject
Then another masterpiece arrived.
Sender:
Anushka Chatarjee
Another Gmail account.
Subject:
<no subject>
The message was sent using BCC, suggesting I may simply be one of multiple recipients who received the same message.
And what's in the email?
Nothing useful.
But, naturally, there's a 390.8 KB Microsoft Word attachment.
So now the pitch has been reduced to:
Hi.
Actually, they didn't even say hi.
It's basically:
Here's a Word document. Open it.
That's the entire sales presentation.
The Attachment IS the Email
This is what people need to understand about messages like these.
The lack of information isn't necessarily a failure.
Curiosity can be the social-engineering technique.
The first email wants me wondering:
Did I accidentally order something?
Was my credit card compromised?
How much did they charge me?
What did I supposedly buy?
And where should I look for the answer?
Inside the attachment.
The second email is even more direct.
There's no story at all. Just a mysterious Word document.
The scammer doesn't necessarily need me to believe anything yet.
They just need me to open the file.
Why I Don't Open Them
I don't know what's inside either attachment because I didn't open them.
That's important.
I'm not going to claim these particular files contain malware, malicious links or credential-stealing software when I haven't analyzed them.
I also don't need to.
An unexpected attachment from an unknown Gmail account with no legitimate explanation for why I'm receiving it has already failed my trust test.
The safest question isn't:
“I wonder what's inside?”
It's:
“Why would I open this?”
And in both cases, I can't come up with a good answer.
The Fake Order Trick Is Particularly Clever
The fake-order approach adds another psychological ingredient:
Fear.
Imagine someone receives the first email and thinks:
I didn't order anything!
That's exactly when rational thinking can get replaced by urgency.
They want to find out whether someone used their credit card.
They want to know how much money was charged.
They want to cancel the transaction.
So they open the attachment.
That's why, if you receive a suspicious purchase confirmation, don't use the mystery attachment to investigate it.
Check your credit card or bank account independently.
Log into Amazon, Walmart, PayPal or whatever company supposedly processed the purchase by going directly to the service yourself—not through links or attachments supplied in the suspicious message.
If there's no transaction, there's nothing to cancel.
From “Pharmacy Office” to This
Just days ago, I received another email with the subject “Pharmacy Office.”
That one also contained mystery attachments with practically no explanation.
Now I've received a mysterious order confirmation and a completely blank email carrying a Word document.
There seems to be a theme developing:
The scammers want me to supply the curiosity.
Sorry.
I'm fresh out.
My New Attachment Policy Is Pretty Simple
Unknown sender?
Unexpected attachment?
No explanation?
Generic Gmail account?
Fake urgency?
Mystery purchase?
I'm not opening it.
If someone legitimately needs me to review a document, they can identify themselves, explain what they're sending, and give me a reason to expect it.
Until then, your mysterious 390.8 KB Word document can remain a mystery forever.
Sometimes the safest click is the one you never make.
Follow along at NielFlamm.com/blog for more scams, suspicious emails, questionable recruiters and the increasingly creative ways strangers on the internet try to get me to click things.
Pharmacy Office? Sure. Let Me Open These Mystery Attachments…
Another day, another email apparently hoping curiosity will overpower common sense.
This one arrived with the wonderfully official-sounding subject line:
“Pharmacy Office”
Oh, good. The Pharmacy Office!
Which pharmacy?
What office?
Why are they contacting me?
Apparently, those are minor details.
The sender identifies herself as “Jessie Smalley,” but the email address displayed with the name is a random-looking Gmail account:
hoangthai96tp@gmail.com
Nothing screams official pharmacy correspondence quite like that.
But the best part?
There is essentially no message.
No:
“Hello Niel.”
No:
“We're contacting you regarding your prescription.”
No explanation of who they are, why they're contacting me, or what I'm supposed to do.
Instead, I get two attachments:
ATT00001.txt
ATT00002.txt
Each is only 244 bytes.
And there they sit, practically whispering:
Come on, Niel. Open us.
We're probably important.
Maybe one of us contains information about your extended car warranty.
Nice try.
The Attachment Is the Bait
This is one of the simplest tricks in the scammer toolbox.
They don't necessarily need to write an elaborate story if they can get you curious enough to interact with an attachment.
The vague subject creates just enough uncertainty.
Pharmacy Office?
Did my pharmacy send something?
Is there a prescription problem?
Is this about insurance?
Do I owe money?
And that's precisely why I didn't open the attachments.
I don't know the sender. I wasn't expecting the email. The sender's address doesn't connect to a pharmacy, and the email provides no context for the attachments.
That's not a reason to investigate the files.
That's a reason to investigate the email.
Congratulations, You Have Failed the Trust Test
If my actual pharmacy needs me, they presumably have several better ways to communicate than:
PHARMACY OFFICE
Two mystery files attached.
Good luck.
Even if an unexpected attachment looks harmless—whether it's a TXT, PDF, Word document, ZIP file, or something else—I won’t open it just because somebody successfully delivered it to my inbox.
And scammers don't always need the attachment itself to infect a computer immediately. An attachment or document can also be part of a larger social-engineering chain intended to send someone to a malicious website, request credentials, provide instructions for contacting someone, or move the conversation somewhere else.
The objective is simple:
Get you to take the next step.
Curiosity Isn't a Security Strategy
These particular files may contain nothing malicious.
I'm not going to open them to find out.
That's an important distinction.
I don't need to prove something is malicious before deciding I shouldn't interact with it. An unsolicited email with no meaningful message, an unknown sender, and two mystery attachments give me absolutely no reason to trust it.
If something supposedly comes from your pharmacy, bank, employer, insurance company, delivery service, or another organization you actually use, don't rely on the contact information conveniently supplied by the suspicious message.
Please visit the organization's website or app, or contact them through a number you already know is legitimate.
Scammers, You Can Do Better
We've had fake recruiters.
Fake job opportunities.
Career-service pitches disguised as recruiting.
And now apparently I've reached the mystery pharmacy attachment chapter of the adventure.
At least put some effort into it.
Please let me know when my prescription for unicorn medication is ready.
Tell me Walgreens accidentally filled 700 gallons of cough syrup in my name.
Give me something.
Instead, I received two tiny text files and the expectation that curiosity would do the rest.
It didn't.
Delete. Report. Move on.
And, most importantly:
Don't open mystery attachments just because somebody was clever enough to put “Pharmacy Office” in the subject line.
Follow along at NielFlamm.com/blog for more scams, suspicious recruiting adventures, and other examples of people on the internet desperately trying to get me to click things I shouldn't.
The Scammers Have Apparently Moved On From Bitcoin — Now I’m Getting My Watch Repaired
Well, the scammers are branching out.
Over the past couple of weeks, I've apparently purchased Bitcoin, renewed Geek Squad protection multiple times, and been invited to Facebook events celebrating these financial accomplishments.
Today, we have something new.
Apparently, I'm getting a watch repaired.
I received an email from something calling itself Watch Repairs USA Customer Care with the subject:
“WATCH REPAIRS USA - Repair #”
Repair number what?
Excellent question.
There isn’t a repair number after the #.
We're off to a strong start.
Thank You for My Payment!
The email proudly announces:
“Your Payment Receipt.”
It then thanks me for my payment and says work on my watch will now begin.
Wonderful!
Except for one minor detail:
I DIDN'T SEND THEM A WATCH.
According to the email, I'm getting a battery replacement for $29.99, plus $30.00 for shipping.
That's some serious shipping for a watch battery.
The transaction information also has some interesting details.
Name: blank.
Address: United States.
That's it.
Apparently, somewhere among approximately 340 million people, there's a watch heading my way.
Good luck, FedEx.
My Favorite Part: “Total $.”
The email lists:
Subtotal $29.99
Shipping $30.00
Total $
That's right.
No number.
Just a dollar sign.
I appreciate a company that lets me use my imagination.
Maybe the total is $59.99.
Maybe it's $5,999.
Maybe they're waiting for me to choose.
This is less of a receipt and more of a financial Mad Lib.
But Don't Worry — There's a Refund Button!
Naturally, the email includes a section titled:
“Request Refund.”
How convenient.
If I didn't complete this transaction, all I have to do is click the nice “Claim a Refund” button.
And that's exactly where my scam radar starts screaming.
An unexpected purchase.
A transaction I don't recognize.
Incomplete information.
Then a convenient button offering to fix everything.
The objective is familiar even though the packaging has changed:
Make me worried about money and get me to react.
This One Is More Interesting
What makes this message different from the recent Facebook event scams is that it looks much more like an ordinary business transaction email.
There's a logo.
There's a payment section.
There's a repair breakdown.
There's shipping information.
There's contact information.
There are links at the bottom.
It has all the ingredients that can make someone think:
“Wait...did I actually order this?”
And that's why unexpected transactional emails deserve a few extra seconds of thought before clicking anything.
A professional-looking email isn't proof that the transaction is yours.
I'm Still Not Clicking
My approach hasn't changed.
If I receive an email saying I've been charged for something I don't remember buying, I won't click the refund button in the email right away.
First, I'll independently check my credit card or bank account.
If there's no charge, there's nothing to refund.
If there is an unauthorized charge, I'll contact the financial institution using contact information I obtain independently—not whatever is presented in the suspicious message.
The important thing is to avoid letting the email dictate what I do next.
That's exactly what these messages are designed to accomplish.
My Imaginary Spending Is Getting Out of Control
Let's review my recent financial activity according to my inbox:
Bitcoin.
More Bitcoin.
A mystery subscription.
Geek Squad.
More Geek Squad.
And now...
A watch battery.
My imaginary self is apparently terrible with money.
Imaginary Niel has excellent diversification.
Cryptocurrency.
Technology services.
Luxury accessories.
It's practically a portfolio.
I'm just waiting for tomorrow's email:
“Congratulations! Your $799 annual yacht maintenance plan has successfully renewed.”
That'll be disappointing.
Mostly because I don't have a yacht.
Although, based on my inbox, apparently I might.