So cookie gets them into Slack. But how were they able to get into the network, spin up a vm and connect to p4? That doesn't happen with a cookie and MFA token.
They either had a username/password combo already, or support also allowed them to reset the compromised users password (ex through a one time link to set a new pw, or perhaps more egregiously "here is your new password: welcome2EA".
A video call and a few questions could have stopped this. Or a password reset flow that requires some sort of previous information. Would love more details here.