If his account was breached it would most likely be from the malicious use of his token. If so, someone had gotten access to his Discord login token and used it to send messages on his behalf without any need of logging into his account. This completely bypasses 2FA and Discord will most likely not send him an email as they won't even know.