I think the details were pretty interesting, so let me expand your summary:
1. Someone gets permission to hack their friend
2. They find their email / phone number online
3. They lookup old password leaks for the email
3.1. They find their password hash (salted) in the Tumblr dump
3.2. Tumblr turned out to use the same hash for everybody, so the author
finds other accounts with the same hash, follows them to a LinkedIn
leak (unsalted), and successfully recovers the password
3.3. The password turns out not to work (changed some time ago)
4. They end up setting up a fake page to phish their friend
4.1. First phishing attempt produces... the old password that is already
known through point 3.
4.2. Second attempt is modified to reject user input a few times, producing
another password, which happens to work
4.3. The victim grows suspicious of the phishing e-mails, but another
message puts those suspicions to rest
5. They wait until their friend falls asleep to reset the Twitter password and (later, in the same way) capture
their LinkedIn account
6. They photoshop their profile pictures to subtly include a Mario character, and they
make their friend follow a bunch of fake Mario accounts on Twitter
6.1. When that doesn't get noticed, they redo the trick in a much less subtle way
7. Friend notices, they meetup to swap stories (the friend doesn't follow the fake Mario accounts)