It was attached to an email that was very similar to one that's received from a company printer when sending a scanned doc. I have a colleague with a very (very!) similar name and we often get each other's emails. Hence I opened the pdf.
Our IT dept has taken little interest, other than sending a warning email several hours after the spam was received - which suggests that more than me opened the pdf. They don't know if other emails in my contact list have been compromised or if the spammers have viewed my emails. They've only advised me to contact VA with queries about IP's, access times etc and to feedback on the apparent ease of access to my account. The spamming has slowed to a trickle, maybe 10 a day, and the filter gets most of those. We have 2FA for accessing outlook via the web but I haven't received any notifications.
I am worried about hacks in the future, mainly because I use my work email for pretty much everything, including personal uses (banking, super, shares, and shopping etc etc).