I strongly suspect that it can be compromised under both of the following conditions:
1. You take recording A, then you take recording B at a time and place which you want to assert that recording A took place at. You recover the thumbprint from recording B, suppress the thumbprint in recording A, then apply the thumbprint from B to A.
This is not a trivial process, but you only really need a plausibly consistent result. A reasonably basic understanding of signal processing theory, a copy of MATLAB, and many pots of coffee should do the job. Then, you could automate most of it for the next guy.
2. You take many recordings at a series of locations of interest, while taking data about the power grid from nearby locations and from distribution nodes. You then attempt to predict the signal at a location from the characteristics of the surrounding area.
This is almost certainly possible, as generalization from distribution logs to the local effect is what makes their fingerprinting technique possible in the first place. It is not a trivial undertaking, and it's questionable how well it would be generalizable. But at the same time, it's largely a question of if you want the data badly enough to do the legwork, and whether you have a reasonably functional understanding of machine learning.