But you could try ~100 password variations and then attack the 2FA.
Up until recently SMS 2FA could be broken for $10 because one VOIP provider allowed number registration on any number.
If you can filter 10,000 accounts down to 100 with known passwords, now you just have to bypass 2FA on 100 accounts.