The 2FA/TOTP security theater was partly to blame for this.
How so? Has the author mentioned somewhere that he was tricked into providing 2FA codes / had any sort of 2FA enabled at all?
A spearphishing email telling them they had to update their 2FA was the vector.