Solarwinds hacked by bypassing 2factor auth via duo akey (OutlookWebAccess servr
arstechnica.com
arstechnica.com
So, they just sat on the key until they needed access to someone's account. Changing that key every 'N' days would reduce the attackers opportunities severely. Then again, changing keys all the time also has it's downsides.