Thanks to this topic I was cautious and today when I saw a suspicious mail I did not respond. Unfortunately, my friend seems to made an mistake. Damage is not big because he did not have ETH in his wallet. Just some tokens. As far as I see on MEW site, there is now a recommendation to install EAL or to use MetaMask in order to protect your self from phishers.
Sorry about your friend's loss, it could have been big if he had a lot of funds or tokens in his wallet. The most important way of protecting yourself is just to make sure you are not clicking any external link from your mail as long as it is not a verifiable operation directly from the site itself, which I believe MEW doesn't even do.
Also, though still under little development, but still very usable, there is an application (at least, I know that of android), that allows you to have access to your private key and you can also view your token and transact directly without having to use your PK all the time to login via the web wallet. Work is still being done to allow sending of tokens anyway, but it has been good for safety. Ether wallet is the name for those who may care.