Adding 2fa does not completely close the exploit window, but it does reduce it considerably. Even if the phishing page prompted for 2fa, those credentials would only be valid for the next ~60-120 seconds, so any attack would have to be staged very quickly.
In this example, they waited three days before trying to utilize the broken account; with 2fa they would not have that luxury.
And this (asking for 2fa in the phishing page) would entail a risk as well; if they prompted a user who did not have 2fa for their 2fa credentials, then they would immediately be (at best) confused, and possibly suspicious, so they would have to decide to take the risk as to whether to attempt to target 2fa'ed accounts. And if they don't offer a 2fa prompt, then the phishing attempt has fizzled, as even with the password, they only have one factor.
Any sort of re-ordering of the login process by the good guys is only effective if the customer is extremely suspicious of changes in the login process, which nobody will be. The phishing site is under no obligation to match their flow to that of the faked website unless not matching by itself would be suspicious.