Two-factor authentication is generally good advice. The version delivered by text message is the weakest common form, and the reason is how phone numbers work.

A phone number is an account, not a device

A number is a record held by a carrier and mapped to a subscriber. It can be moved to a different device or a different carrier through ordinary customer service processes.

Those processes are designed for genuine customers who lose phones or switch providers, and they rely on identity verification performed by a person under time pressure.

An attacker who persuades that process to move a number receives the messages sent to it, including verification codes, without touching the victim's phone.

The information needed is often purchasable

Verification frequently uses details such as address history, date of birth or account information, much of which is available through data brokers and public records.

This is why the strength of a text-based factor depends on a carrier's procedures rather than on anything the account holder does with her password.

Interception is not the only route

Codes are also obtained by simply asking. A caller claiming to be from a bank's fraud department requests the code the victim just received to confirm her identity.

The code is real, the login it completes is the attacker's, and no technical compromise occurred at any point in the sequence.

No legitimate institution asks a customer to read back a verification code, and that rule is worth holding absolutely rather than case by case.

Stronger factors do not depend on the carrier

Authenticator applications generate codes on the device itself with no message in transit, which removes both the carrier and the network from the process.

Hardware security keys go further by verifying the site's identity as well as the user's, which defeats the credential pages that defeat everything else.

The comparison that matters

Any second factor is substantially better than none, so a text-based code should not be turned off in pursuit of something better that never gets set up.

The account worth upgrading first is the email address used to reset every other password, since control of it is control of the rest.

Carriers also offer account locks that block number transfers without additional authorization, and requesting one is a short call that addresses the underlying mechanism directly.