There are operational red flags but not the ones you mentioned. What a lot of people forget in these situations is that these are support agents and they need access to customer data to do their job. Additionally, I bet accessing 300 accounts per week is a totally normal thing for a support agent to do. Sure you could write some alarms that trigger in certain cases but it’s very hard to do without creating alarm fatigue.
The issue here is that 1) an employee was able to be phished and/or have malware installed on their device and 2) support agents should only have access to accounts where they have been assigned a ticket, and agents should have no control over which tickets they get assigned.