If his service was purely playing an automated IVR message and the live call center he hot-transferred to was someone else, I could see him making a custom solution to cut costs. But it'd be fairly easy to make that volume of calls via most enterprise level autodialers without raising any eyebrows as long as there were enough agent licenses to support it.
Most autodialers bake in regulatory compliance functionality and warnings, but the laws that apply are so specific to an individual user that those features can be disabled or overridden and they leave it up to the client to understand what laws their calling must adhere to.
For example, the guy in question would have been legally fine to spam 100mm calls in three months if they had been business landlines, as the federal law they're leveraging for their fine only applies "to emergency phone lines, wireless phones, or residential telephone lines"[1]
[1]In the first paragraph of the order: http://transition.fcc.gov/Daily_Releases/Daily_Business/2017...
:) I hate to break it to you, but phone companies aren't really all that interested in shutting anything down. It's a multi-faceted problem. There isn't a good (agreed upon) way to authenticate calls. Even if that were the case, phone companies are not going to be jumping on the idea of retrofitting the old parts of the network with reverse proxies for this new authenticator.