She gets a lot of company and client-generated PDF and document attachments with her e-mail.
-40hz
With the popularity of Multi Function Printers these days, many companies are going paperless-er. And it seems like a lot of the people that set these things up always leave the default subject line in the scan to email configuration. Se people being used to accepting 'Xerox/HP/Lexmark/whatever model X created document' for a subject line while dealing with 50-100 of these a day can make it easy as hell to miss a bad one. Especially if the attacker matches up the default naming convention of the manufacturer with their name ... Or picks something inconspicuous and relevant like Invoice, Receipt, or Purchase Order.
This happens mainly because nobody wants to have to stand there in front of the damn thing and type a bunch of anything in on one of those tiny assed touch screens. So default, default, default, and send it is. Every friggin time.
Anytime I have to setup scan to Email on one of these devices - which happens a lot given the business we're in - I change the subject line to something that is relevant to the sending company to avoid having their Emailed scans adding to the problem.
Given the popularity of the technology, and ease of blending in...those things can be a real bitch to spot. And as a card carrying BOFH, it truly pains me to say it ... But it's damn hard to blame the user for missing one of these.