Social engineering is great, we do it at work all the time to test our security procedures.
We had one where one of our security people faked an email from our MD saying that they had been selected as they were good employees to enter a prize draw for a free holiday.
He had done a nice looking web page, that asked them to enter their network password, around half the people "selected" did so and effectively gave their passwords away to someone else.
There are quite a few security companies doing this kind of thing, one even got people to give away their passwords for a
bar of chocolate.
Jen