“The thing that’s crazy is that if I followed the 2 “best practices” of verifying the phone number + getting them to send an email to you from a legit domain, I would have been compromised.”

The caller ID said Google. The email came from a real g.co address. The callback number was listed on google.com. Every best practice pointed at the attacker, because Google let anyone send mail from a g.co subdomain.