Why can mobile providers be still so easily social engineered to this day? Seems like calling them and activating a new SIM (i.e. stealing a number) is still quite easy.
Defending against social engineering attacks is HARD, because the only real mitigations against them could also result in locking out the real owner of the account.