The industry needs to learn that sms 2fa is not secure because getting a sim for someone else is so easy. And this happening in every country.
I would say that for the average user sms 2FA is secure enough. P.S. I might have a different perspective as where i am from, there really aren't important services (banks etc.) that are using sms 2FA. Mobile operators doesn't ship SIM cards over mail, you can get a new SIM only in person providing ID (or PIN/PUK in case of prepaid cards). Probably my country is just too small market for these kind of attacks so i fe…
As for how hackers can swap someone's SIM, consider:
- Does the 20 year old minimum wage employee working at that store know how to spot a good quality fake ID card?
- What about hackers bribing an employee?