There was always social engineering, like Rob mentioned
Me, after a pentesting company had given $EMPLOYER their shpiel: "And do you use social engineering?"
"No, we never do that."
"Whyever not?"
"Because it *always* works, so we don't learn anything."