The major crux of this article is the paragraph where it talks about how regulations essentially allow phone carriers to do whatever they want, with no guarantees of security, no indemnity, and if anything goes wrong there's no repercussions whatsoever.
There is literally nothing you can do to prevent this, any kind of "flags" or "extra security" you request are entirely enforced at the whim of individual call center personnel, and it only takes one person to ignore them. My case was similar to the article, I had some basic security flags enabled on the account but they were buried in notes from calls years ago and obviously no CS rep is going to read through years of notes on every call.
In my case the attackers called Sprint customer service over 100 times over a 5 day span. On the day I was breached they called 12 times within 3 hours before a weak link allowed them to transfer my number. No alerts to myself or the account holder, no notifications, nothing. The first rep I called after this occurred gave me great detail into the calls and what they had asked, apparently some of the numbers even came from different European countries. I immediately tried to escalate to their fraud department and was stonewalled hard. The fraud people denied any pattern of calling into their support lines, denied any transfer of my number (even though reps later happily helped transfer it back from Google Voice), and denied any action on the part of Sprint that caused this to happen.
Lawyers essentially told me I was out of luck, there was no recourse unless I was willing to go to war in the courtroom and unfortunately I don't have _that_ many old BTC.
It is absurd that such telecommunications backbones have such lax policies, much less no repercussions when they screw up. This will continue to be an attack vector until we force some sort of regulation that requires extraordinary damages to be paid per case... something tells me even low fines and slaps on the wrist won't incentivize the telecoms to provide actual customer service.