Manipulating people is more interesting in some ways than exploiting a bit of badly written software because while I write terrible code all the time, I could fix it too but there's no patching our stupid stupid brains. We can try to be more careful, and avoid falling for things others have already, but the flaws are still there just waiting for the moment our guard is down.
Some human exploits can be patched, at least partially. 2FA with hardware authentication helps prevent people from leaking their own passwords and such. Phishing detectors help. Etc. I'm sad to admit my wife is better at this than me. Any time anyone she doesn't know tries to talk to her, she's quick to escape. I tend to try to politely decline, she just books it
He was very good at that segment of the industry ("penetration testing" via social engineering).