Common fallacy is that phone numbers uniquely identify a person or a geographic location. Neither has ever been true but that is the real reason banks want your phone number so bad. It wasn't so long ago that you couldn't even get a loan or credit card in the US without a phone in your name.
My phone number came from an old alt.phreaking post and has run busy continuously since at least 1982. If banks try to SMS authenticate me then instead of their app or web banking, I just link the account to another bank that doesn't do SMS. These days I pay for everything with credit cards anyway and the bank is just there to insure and hold my funds until I pay the cards, so I don't need much from them besides an ATM card and the ACH numbers.
I've noticed that all of the synchrony branded credit card sites require SMS only for password changes, and when prompting you they pull a list of every phone you've ever owned from a Transunion skip-trace database. If they wanted to authenticate me again before entering an area of elevated security they could just ask for my password again - but they don't, and they don't ask for any credentials when changing the phone number, so that suggests to me that security isn't the reason they are prompting for SMS authentication.
SMS validation or not, don't try to access the web portal for a Synchrony issued credit card from outside the US, they typically block the account with SMS validation for 3-4 days. Several times I've forgotten to turn of my VPN and ended up sending them paper checks in order to pay my bill on time.
Plus I think we've sufficiently proven that phone numbers are susceptible to SS7 and social engineering attacks, anyone with my mother's maiden name, DOB, and social security number can take over my phone and all the information is easily acquired from Transunion or Experian. The best thing NIST ever did as depreciate SMS auth for all the reasons I just described. The worst thing NIST ever did was backtrack on the first thing.
There are financial services companies out there that give a damn about security. Shout out to Robinhood for enabling strong passwords (32 characters!) and standard TOTP. They are the only financial services company I've found that offers TOTP. As soon as they have a cash management account I think that is where I'm going to park my funds.
(E*Trade has 2FA also but you have to buy a hardware dongle from them. I appreciate the effort but paging Captain Marvel just the same.)