Earlier quoted context omitted.
This. It would be unbelievable if Twitter's internal system doesn't require VPN/BeyondCorp or 2FA before doing anything sensitive.
If the employee re-used a hacked password and had 2FA via SMS it wouldn’t be hard.
Such social media platforms have to be tamper proof even from the CTO, the reddit incident proved that years ago.
This is going to hurt their credibility hard in the run up to the election.