Shame on T-Mobile. That said, perhaps everybody using SMS 2FA is equally culpable (e.g. most banks). Nobody who has worked at a mobile carrier would ever think that they're ready to be high-value targets. So it's puzzling that the banks are so eager to put them in that position.
The order of shaming should be: 1. Businesses using insecure channels to do authentication and validation. 2. Mobile carriers
I'm imagining an authorized pen-tester program which lets authenticated users achieve an atomic sim-swap (i.e. the creds were intercepted but the swap-back occurred immediately after, so as not to deny additional service to the victim).