All secrets eventually leak. It's a question of time. Not even state actors with unlimited resources can prevent secrets from leaking. So this wasn't bad operational security by authorities. It was a fundamentally flawed operation.
Security through obscurity has limited and unpredictable usefulness. Good OPSEC can delay a leak, maybe. But OPSEC is still much harder for defenders than attackers.
The article doesn't mention it, but SURELY agency planning about this particular secret covered the next steps to take when it leaked.
Ordinarily good OPSEC has defense in depth. Secrets should have limited useful lifetime. "Stingray" as a secret doesn't: once bad actors know their phone locations can be targeted, they can't un-know it.
It should be obvious to the holders of secrets when they leak, so they know they're compromised. Having this "Stingray" crop up in a big mess of bankers' boxes full of court docs isn't obvious.
Security by obscurity needs a plan B ready to roll at any time.
Much better is transparent security, where the tech is well known, the actual secrets have limited useful lifetimes (key-rotation and forward secrecy for example), and reasonable controls exist (search warrants in this case).
If law enforcement executives don't know this, they need to go back to school. But they probably do know it, and they're practicing security-by-obscurity on their plan B.
(I don't defend somebody who stole large quantities of taxpayers' money. Not at all. But the rule of law--search warrants--is vital.)