I agree ... to a point
But this statement is simply not true
>any user of Linux would know if an email attachment asked for an administrative-level password, shenanigans were afoot.
Every IT support professional knows that you cannot underestimate the stupidity of the end-user. If the email was phrased correctly then some would.