I believe HR is commonly targeted by attackers, precisely because they have access to sensitive personal information on their employees. I used to work at a company where a high-level HR employee received an email purporting to be from the CEO, asking for a list of all employees and SSN's. Rather than asking critical questions about this request, they simply collected the requested information into a spreadsheet and emailed it to the attacker. Presumably all of our information was subsequently sold to identity thieves.