I presume from the article an email account was hacked (password available?), which gave means for a Coinbase password reset, and then a SIM swap occurred on his account leading to a withdrawal.
One might argue Coinbase has a duty to do more here -- nothing on their site (at least the security/mfa section) suggests SMS isn't good enough. PcMagazine[1] suggests 95% of users rely on SMS 2FA/MFA, and Coinbase seems aware that these phishing campaigns are happening against SMS 2FA/MFA [2].
[1]: https://www.pcmag.com/news/95-of-coinbase-users-rely-on-sms-...
[2]: https://www.bankinfosecurity.com/crypto-exchange-coinbase-de...