Earlier quoted context omitted.
From memory, I recall the FBI did a study, and found that half of their employees would plug in a USB drive that they found on the ground in the parking lot. After training, that number was reduced to a quarter. If a security-focused government police agency is so vulnerable, it is unreasonable to expect perfection from a (less paranoid) company.
I wonder what sort of machine those folks were plugging it into? If it's their general purpose work issued machine, shame on them, but I can't believe the FBI doesn't have a high and low side networks. How many plugged into the high side? How many plugged into the "this is my email and timecard" computer? I have a Chromebook running arch[0] that has a borked network adapter than I use to plug weird things into/use as…
As an aside to that important point, it seems like the solution here is to just remove all random device access points and drives before giving a system to some luddite with no security awareness.