Sounds like they are saying the agent did not malfunction, and this vuln could have been triggered by a human support agent too.
Humans support agents certainly fall prey to social engineering all the time, but I can’t think of a case where it was done on this scale so easily.
Having a support agent likely made it easier to enumerate the vuln, and certainly made it easier to scale out exploitation once it was discovered.
But it’s irrelevant, outside of PR. We know at least THREE bad components to this process and they were constituent parts.