It depends. Sometimes a person thinks he/she's so smart(and so confident, in this case with his wallet security setup) that he/she gets complacent. Even smart and very technical people can get really careless.
Saying too confident might not be right, he was just careless and assumed everything was safe so he didn't check every place whether was safe or not.
If his server is infiltrated by malware, most likely that is the cause, because a few months ago the server was entered by an unknown person.
When smart people get too careless, there's no meaningful security, anything can be hacked regardless of who that someone is.