Yeah, but it's an order-of-magnitude more complicated. It's no longer "click a link and fill in your creds on a legit-looking website", it turns into "hack someone's email, request a password reset, wait the mandatory 24 hours, do a social attack on the provider to pull off a sim swap, and fill in the 2FA code".
> Your master password to your cloud PW manager's vault is also phishable
... which is why all sensible cloud vaults have a separate enrollment key, requiring an explicit action to grant a new device access.