tl;dr: "Kroll’s website says it employs “elite cyber risk leaders uniquely positioned to deliver end-to-end cyber security services worldwide.” Apparently, these elite cyber risk leaders did not consider the increased attack surface presented by their employees using T-Mobile for wireless service."
https://krebsonsecurity.com/2023/08/kroll-employee-sim-swapped-for-crypto-investor-data/
Yes, much of the blame rests (as usual) with T-Mobile, which has yet to respond to this.