Two insights. One from the article itself

> In our day-to-day work these threats appear rarely.

Two: IRL the attacker pays a small amount of money to a low salary employee to exfiltrate data.