Interesting but far from an account compromise on it's own. You still need to know the user's password in the first place and, I believe, you can't repeat the attack once they change their password. So if they change their password a second time or enable MFA themselves you're blocked permanently. So it allows for a existing attack to be prolonged one time and possibly makes it harder for a user to realize they're still compromised.
I can see some value in a targeted attack on an individual although only if they don't respond by turning on MFA themselves.
I can see some value in a targeted attack on an individual although only if they don't respond by turning on MFA themselves.