I would answer that rhetorical question with no, HR departments have not have heard of social engineering attacks in computer security. Almost any company asking for a password will have a brain-dead HR department in charge of that policy; it's not like your fellow future programmers thought that one up.