Earlier quoted context omitted.
But one point of the article was that he did have MFA - and it's no use in this scenario (attacker had physical access to second factor)
It's not really MFA if it's all done on your phone.
Aside: It's something I worry about sometimes too on phones...