This sort of nonsensical reasoning has also used by individuals portraying themselves as "whitehats" who try to profit from large leaks of personal data. Users are asked to provide personal data to the whitehat in order to confirm whether their personal data has been leaked.
They obviously have enough engineers and awareness to do software based OTP, and clearly only want SMS for their phone number social graph and data brokering operation.
So, LOL FTC.
It's certainly a violation of trust that could make people less likely to volunteer extra information for 2FA that could be used against them, even if it might also make them safer. For that alone, wilful violations ought to be treated as a serious breach under data protection laws.
The number of important financial services I use that now insist on phone numbers for 2FA is getting irritating, too. Apparently in some cases it's been prompted by the changes in EU rules under PSD2, but as with almost everything else I've come across so far under PSD2, I'm not sure how much safer it will really make anyone. At least those financial services -- and my government, which is the other organisation I see doing this routinely now -- probably aren't going to use the contact information for anything other than the 2FA they claim, though.
In general, SMS is better than no 2FA, but it's weaker than OTP/OTH or a token like YubiKey or Titan.
And IIRC at the time Twitter didn't offer any other 2FA mechanisms.
Trust me, if our agencies had teeth, and executed a corporation for shit like this, we'd have a better technology ecosystem.