Most likely down to inexperienced employees who have not been properly educated on cyber-security. It is a cold world and if you want to be protected against scam attempts like this then you need to become educated.
If only companies spent a bit more time actually training their employees than just slapping on some end-point protection and assuming they'll be bullet-proof or never targeted.