The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.
SMS 2FA is fine. 2FA adds another layer on top of your password. The second factor doesn’t have to be particularly secure to make you safer. The problem is SMS account recovery , which is a really bad idea.
The problem is that a lot of services tie the two together. Often one implies the other. Even if it doesn't, though, it's also easier to social engineer -- "look! I have access to the 2fa phone number! I just can't access my password manager!"