One take away is how SMS as 2FA depends on a flawed assumption. The other I found cute is using random strings as answers to the stupid account recovery questions companies continue to ask.
Things not mentioned in the blog is exactly what personal information the attacker had, that authenticated him to Verizon. PIN? Some portion of his SSN? It must not have been account recovery questions because the target of the attack used random strings as answers.