I’m also a NordVPN customer, and not only I do not use 2FA, I deliberately use easy to guess, previously compromised passwords. I’ve also handed out those credentials to plenty of my friends.
Just in case they happen to log the network activity of their users, what this can achieve is plausible deniability and noise. Lots of noise.