It's possible that the TOS message is boilerplate that they put up when they haven't created (and localized) an appropriate message for the real reason (or they don't want to reveal the real reason). To me it sounds like maybe they detected a successful credential stuffing attack against the accounts and locked them. That said, it sounds like their recovery process leaves a lot to be desired.
I had a gaming-only Microsoft account locked in the same way and I can guarantee you there is no successful credential-stuffing attack against it (even the username was secret, as it was random and not used anywhere else). Locking accounts for "security reasons" and requiring a phone number is a common tactic to harvest phone numbers for "growth & engagement" reasons. Twitter does that since a while ago and recently…
From a security standpoint, the point of requiring a phone number is to increase the expense of the request -- like a captcha.
(Not to say that there is a real security purpose in this specific case.)