Pharmacy Office? Sure. Let Me Open These Mystery Attachments…
Another day, another email apparently hoping curiosity will overpower common sense.
This one arrived with the wonderfully official-sounding subject line:
“Pharmacy Office”
Oh, good. The Pharmacy Office!
Which pharmacy?
What office?
Why are they contacting me?
Apparently, those are minor details.
The sender identifies herself as “Jessie Smalley,” but the email address displayed with the name is a random-looking Gmail account:
hoangthai96tp@gmail.com
Nothing screams official pharmacy correspondence quite like that.
But the best part?
There is essentially no message.
No:
“Hello Niel.”
No:
“We're contacting you regarding your prescription.”
No explanation of who they are, why they're contacting me, or what I'm supposed to do.
Instead, I get two attachments:
ATT00001.txt
ATT00002.txt
Each is only 244 bytes.
And there they sit, practically whispering:
Come on, Niel. Open us.
We're probably important.
Maybe one of us contains information about your extended car warranty.
Nice try.
The Attachment Is the Bait
This is one of the simplest tricks in the scammer toolbox.
They don't necessarily need to write an elaborate story if they can get you curious enough to interact with an attachment.
The vague subject creates just enough uncertainty.
Pharmacy Office?
Did my pharmacy send something?
Is there a prescription problem?
Is this about insurance?
Do I owe money?
And that's precisely why I didn't open the attachments.
I don't know the sender. I wasn't expecting the email. The sender's address doesn't connect to a pharmacy, and the email provides no context for the attachments.
That's not a reason to investigate the files.
That's a reason to investigate the email.
Congratulations, You Have Failed the Trust Test
If my actual pharmacy needs me, they presumably have several better ways to communicate than:
PHARMACY OFFICE
Two mystery files attached.
Good luck.
Even if an unexpected attachment looks harmless—whether it's a TXT, PDF, Word document, ZIP file, or something else—I won’t open it just because somebody successfully delivered it to my inbox.
And scammers don't always need the attachment itself to infect a computer immediately. An attachment or document can also be part of a larger social-engineering chain intended to send someone to a malicious website, request credentials, provide instructions for contacting someone, or move the conversation somewhere else.
The objective is simple:
Get you to take the next step.
Curiosity Isn't a Security Strategy
These particular files may contain nothing malicious.
I'm not going to open them to find out.
That's an important distinction.
I don't need to prove something is malicious before deciding I shouldn't interact with it. An unsolicited email with no meaningful message, an unknown sender, and two mystery attachments give me absolutely no reason to trust it.
If something supposedly comes from your pharmacy, bank, employer, insurance company, delivery service, or another organization you actually use, don't rely on the contact information conveniently supplied by the suspicious message.
Please visit the organization's website or app, or contact them through a number you already know is legitimate.
Scammers, You Can Do Better
We've had fake recruiters.
Fake job opportunities.
Career-service pitches disguised as recruiting.
And now apparently I've reached the mystery pharmacy attachment chapter of the adventure.
At least put some effort into it.
Please let me know when my prescription for unicorn medication is ready.
Tell me Walgreens accidentally filled 700 gallons of cough syrup in my name.
Give me something.
Instead, I received two tiny text files and the expectation that curiosity would do the rest.
It didn't.
Delete. Report. Move on.
And, most importantly:
Don't open mystery attachments just because somebody was clever enough to put “Pharmacy Office” in the subject line.
Follow along at NielFlamm.com/blog for more scams, suspicious recruiting adventures, and other examples of people on the internet desperately trying to get me to click things I shouldn't.