points
Same reason security programs exclude social engineering, even though that's a pretty common way for companies to get pwned.