That doesn't help OP now, but I found it helpful to enable 2FA with Google Authenticator, and keep emergency backup codes in a safe place. It's slightly more hassle, but there are less 'soft AI' barriers between you and your successful login. I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.
Well, I have my PayPal account set up with a strong unique password and 2FA via an authenticator app. Recently installed the PayPal app on my smartphone, and it asked for CAPTCHA, password, 2FA token, and then additionally SMS to an old phone number I still had on file. How does it make sense to ask for 3 factors? At any rate, I logged in on the computer and updated the phone number. Still wouldn't let me log in on the smartphone, needed to contact customer support.
Look, I understand that many people choose bad passwords and they get pawned and all, and I'm glad that the providers are a bit smarter and use other factors (cookies, IP, phone number...), but it really penalises security and privacy conscious users. If you use strong passwords and 2FA, but use VPNs, switch phone numbers, clear cookies, etc., you get flagged and locked out. Very annoying.