You can easily generator OTP codes the same as any of the "authenticator" apps using, for example, oathtool [1]
You don't even need the code to be stored on a computer. Just write it down somewhere safe if you're paranoid about getting hacked. The seed codes are usually 16 characters or so.
Whether you consider the SIM swap attack a threat worth protecting from would depend on many factors, even though the threat itself is very real, and almost all phone numbers are vulnerable to the attack. I have yet to learn any phone service provider that is not vulnerable to this attack. I've heard people speculating that Google Fi might be one such provider, but I don't know if Fi customer service actually is not vulnerable.
How exactly does this happen?
Or bribe company staff to give you the SIM card.
Phone company staff are error-prone humans just like you and me who in general don't earn well enough for their responsibilities.
That makes a lot more sense. Thanks!