Of course, there are real risks out there that we need to avoid.
The targeted emails warning of IRS Audits or overdue invoices are a perfect example. Executives receiving these quite alarming emails click on the attachments to find out what the problem is, and the bad guys now own their computers.
I've seen multiple examples of the IRS audit scam, all of which came to executives here at work. Someone's been doing their homework.
I'd suggest warning all executives of your companies about these emails.
Example, from
SANS:
Proforma Invoice for "Company Name" (Attn: "Executive Name")
The Body of the email included this text
"Hello,
The Proforma Invoice is attached to this message. You can find the file
in the attachments area of your email software.
PS: The invoice also includes the cost for the services provided for the
second quarter of 2007.
Please read, evaluate and reply with any comments. Thanks."