As requested via email by that user. (My rights on iridium aren't sufficient to reset 2FA for that user who cannot log in at all anymore.)
I've checked the date and phrase of that user's committed identity sha512 hash blah which the user had sent via GPG-encrypted email.