Earlier quoted context omitted.
The right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.
what would stop a developer from checking personal email on a work machine?
Figure out a company uses register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details.
If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?