Earlier quoted context omitted.
Hey, Any good literature which you'd recommend to read to avoid something like this?
Use U2F for 2FA. If Twitter had all their employees using U2F keys it's very unlikely they'd be phished. With U2F it's impossible to "enter" a 2FA code on the wrong domain, making you immune to phishing attacks by most definitions. This Kerbs article from awhile back says that Google had zero phishing incidents after making this switch: https://krebsonsecurity.com/2018/07/google-security-keys-neu...
I don't know that they even need to go that far. Just U2F on the god-mode admin tool would have been reasonable.