Duo.com, the 2FA scheme Instagram and GitHub uses, and you can use on your own website, does not connect your phone to your account (in the knows your number, IMEI or location sense).
Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
passwords a quite a shitty defence
Duo.com, the 2FA scheme Instagram and GitHub uses, and you can use on your own website, does not connect your phone to your account (in the knows your number, IMEI or location sense).
But you managed to shoehorn CBDC into it again
https://arstechnica.com/security/2024/01/microsoft-network-breached-through-password-spraying-by-russian-state-hackers/