The reason why so many people fell for this attack was because it was carried out through malicious links embedded in documents. These links led to phishing websites but the anchor text of these links was “View Document”. Naturally, no one was suspicious of a text like that.
On one hand, I know we shouldn't blame people for falling for this stuff. People are often not educated well enough on the dangers and it's not reasonable to expect it. We should build things to be systematically secure even in the face of people falling for phishing.
On the other hand it's difficult not to be frustrated with this kind of thing... People really should know better than clicking random links and typing their password.