Doubt it was a hack, read this:
http://www.symantec.com/avcenter/[email protected]
"The email message can be composed with or without the use of the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability to automatically execute on a vulnerable system. "