This is the best commentary on a real-life social engineering hack I've seen. Whats really interesting is how he was able to be undetected mostly, because services like linkedin only had an optional requirement for forcing all devices to re-login when a password was changed, and that the hacked individual wasn't using 2FA on her email.