I nearly got caught ...

I received an email from someone I know well - they use outlane.com email.
There was no text just the attachment shown below - I've replaced names with ***
View attachment 173232
I'm usually very careful but because I knew the sender I clicked the 'Open' button without checking the link within it.
I was signed into Chrome and Gmail and immediately Google flashed up a full screen red warning Unsafe so I did not proceed further. To be safe I've changed my Gmail password, run Windows Security offline virus check and thinking about changing my Microsoft account password.
Chatting with the person I know, a scammer somehow got into his email settings and diverted all his incoming mail to the deleted folder so he did not know anything was wrong until many of his 78 contacts started asking him why he was sending out strange emails.