- You have to have a physical/esim card which costs money to buy and is perfectly Geo-trackable.
- You can only SIM-swap by duping any given cellular operator in personal interaction with their Support. Article says US & Europe - different countries, different mobile operators. Each such call is recorded, costs air time money, again Geo locates the caller.
What is more probable - yet another stupid malware was installed on phones, which can easily read Device ID/SMS received. In such case, great that Trusteer busted this operation (I guess, no mentioning of LE involved), but nothing news-worthy in technological sense. So, it is still better to have SMS as MFA versus no MFA at all, and of course it is time to switch to Authenticaiton Apps for MFA/Hardware keys.