> SMS - it's just too easy for SIM swap attacks, and good social engineering to phish SMS codes. "Hi, this is $BANKNAME - we saw some suspicious activity on your account, so we are going to send a one-time code to you now. Please enter it back to us here to verify your identity" (scammer then uses your stolen password, tries to log in, real bank sends you real code, which you now are tricked into sending to scammer to complete their login as you).
First three DDG hits for "SIM swap attack" are https://www.consumer.ftc.gov/blog/2019/10/sim-swap-scams-how... and https://us.norton.com/internetsecurity-mobile-sim-swap-fraud... and https://privacypros.io/u2f/sim-swapping/ .
Here's a recent news piece on the topic: https://www.lightreading.com/security/heres-how-atandt-veriz... ("The FCC has received numerous complaints from consumers who have suffered significant distress, inconvenience and financial harm as a result of SIM swapping and port-out fraud".)