Of course was the account was hacked.
This kind of attack is called email spoofing, the hacker use a hacked email and us a known email from your known list , then they send a email you recognize as your friends, with an attachment but coming from another email.
Generally the users does not...