How is that social engineering? It doesn't seem like human behavior played any role in this at all. The hacker interacted only with automated systems.
This is a security bug that was exploited. It should not be possible to reset a password without the 2-factor auth code, period. If that is possible, then that the 2 factor auth is broken.
When people say 2-factor auth code is broken, it implies there was an issue with the 2-factor authentication code itself.
That would mean things like RSA and other Token based authentication might be at risk. So no 2-factor auth is not broken. Authentication in Google is broken.
Well of course the concept of 2-factor auth is still sound. No inherent flaws in the math or the theory. But this particular implementation is quite broken.
This is a security bug that was exploited. It should not be possible to reset a password without the 2-factor auth code, period. If that is possible, then that the 2 factor auth is broken.