Why build hacking tools when you can steal them? Or at least get an idea of what tools your target company was red teamed with.
Why spy on your own citizens when that makes them blackmail-able by foreign nation states? Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.
No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that it's tapping into their phone line using SS7. Probably the hardest way is to first hack a security agency, which I'd imagine have some of the better intrusion detection out there.