From what I understood, they didn't use some kind of software exploit, but it was all about social engineering. Which prooves that MFA that is not phishing-resistant like authentication apps, are really not good enough any longer.