https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...
Most people in jail didn't think or care about what could go wrong.
The employee was likely a customer service rep. Incidents like this have happened before at Twitter, in 2017 a customer service rep at their San Francisco office deleted Trump's account:
https://www.abc.net.au/news/2017-12-01/trump-twitter-employe...
> When the hackers were instructing the employee to post these tweets...
The employee didn't post the tweets, their involvement was changing the email addresses on the accounts they were told to (which bypasses 2FA). The Krebs article shows screenshots of the Twitter customer support dashboard for an account:
https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e...
Between that and just bribing support people (or they were in on it to begin with), you have the two of the most common attacks on user/customer data.