2FA via SMS requires a private channel, but SMS wasn't built to be end-to-end encrypted (although it could be, using the SIM's processor, such a proposal will be shot down by the state actor members of the relevant standards body. See the less-than-perfect security profile of 5G), and so whenever a message is diverted within the system, somebody else can take over.
M-Pesa requires message to be trustworthy, and the SIM app can sign them with a key that resides only on the chip. The transactions are probably not very private (so it might be possible for an eavesdropper to figure out that user A sent X currency units to user B) but that's not a make-or-break requirement for the system to do its job (unlike for 2FA via SMS).