Microsoft has been under attack by state actors for decades now, their security teams work hard to keep things together but even a company like Microsoft will fail when literally every large country is attacking them 24/7, including going so far as to get spies hired into the company.
Microsoft was historically very locked down internally, unlike Google where all source code was visible to everyone, Microsoft had (may have changed not sure) product code based cordoned off.
As for bypassing TOTP, does TOTP provide any security if running on a cell phone and the cell phone is rootkitted?