Yes, that is a social engineering attack, not a hack.
E-mail is not secure, everyone knows it. You should always verify important matters over some more secure medium, preferably multiple ones. Even a phone call would have been enough to prevent this.