> How was 2FA bypassed here?
very likely a sim swap attack:
"A SIM swap scam is a type of account takeover fraud that generally targets a weakness in two-factor authentication and two-step verification in which the second factor or step is a text message or call placed to a mobile telephone." [1]