1. You have a unique, long password with Foo.
2. Oh no! They store your password in plaintext, and their security is terrible, so your username and password are part of a giant data breach from Foo.
3. Before you know about it and can change your password, someone that is not you, who does not have access to your phone, tries to log into the account.
4. While out living your life (or in, these days), you receive an SMS from Foo, and then ignore it.
5. There is no step 5, as no one else is getting in.
6. Okay, fine, you caught on, and now you log in and change your password with Foo, or maybe just drop the account, because really.
It seems to me that SMS-2FA helps in this scenario. Am I missing something obvious?