>b) whether these specific attacks are still possible.
Why not? It's been proven over and over again that customer support can be manipulated easily. Most companies want their customer support to help the average user. The average user isn't being hacked but instead loses their passwords and access in a variety of ways. The cost of screwing over one customer compared to aiding the rest is nothing to them (because nobody has sued them for it yet and won)
One of the specific attacks was getting the last four digits of a credit card from one company's CSR and using it to authenticate to another company's CSR - I think that happened in a couple of other high-profile attacks around the same time frame and major companies decided that the last four digits wasn't actually a meaningful authenticator.
a) how the account got transferred back (did Twitter support do it)?
b) whether these specific attacks are still possible.