As always humans are the weakest link when securing systems. This reminds me of this thread https://news.ycombinator.com/item?id=28279326 Where the attacker was able to trick Tmobile / Sprint customer service into providing a PUK number.
In the end, in our case, USAA gave us a detailed rundown of how they failed, and then turned up to 11 the security questions my wife had to answer. Every single call she had to give a password, pin code, and then answer the questions that are sourced from Experian(or some other credit bureau) intended to prove identity through knowledge. Every time. They punished us for a mistake they fully admitted was their employee's fault.
Nah, I'm not bitter at all. Ultimately, though, it will be one of the reasons I move my account away from USAA.