This kind of attitude has to stop. "Glorified phishing" might not have pizazz, but it was DAMN effective in this case. Why go to the trouble of finding, coding, exploiting an increasingly difficult target when end users will do all the work for you?
This is the kind of scenario that gives security people nightmares. It takes VERY sophisticated processes and technology to find covert backdoors on your network, and very few places devote the manpower or $$$ to the effort.