There has been several cases on Blockchain.com where 2FA email of the user has been mystically disabled, after which all the funds have been stolen.
All evidence lead to the fact that the person behind the theft is most likely Blockchain.com employee, and was done like this:
1. The employee looked up Wallet IDs and account emails in Blockchain.com system and requested 2FA change via the publicly available form. 2. He disabled email notifications about 2FA change (possibly only for the specific account). 3. Once the 2FA email was changed, he either used a brute-force attack to crack the password or more likely he already acquired it from numerous user-data leaks, which is how he was targeting the accounts in the first place. 4. After gaining access to the wallet, he withdrew all balance to his own wallet.