Have you ever thought about posting something to help people rather than always making it about you!
My friend had implemented 2FA which was invoked when I changed their BT Email password. But BT Email does not require 2FA on a different/new client or browser, notably on a different device. That's why the hacker gained access but was unable to oust the victim from the email account.
Incidently, the link you provided covers 2FA on "My BT". "BT Email" is a different 2FA setting.