Earlier quoted context omitted.
We have had this at Amazon AWS. We had 2FA, one phone call was enough to disable 2FA. The only thing they asked were the last four digits of our credit card.
Too bad you can't ask for the CVV code, and run a dummy $1 transaction. Anyone could have the last four of the card number, but the person is much more likely to have the card itself with the CVV. Disclaimer: I use AWS extensively. Please do this.
Call 2: "I just locked myself out of the account, can you reset it for me."