Isn’t this just a phishing attack? Almost any MFA service is vulnerable to this, but it’s not at all insurmountable if the user is sufficiently trained during the onboarding process. They even have an app which can leverage to help train users around the risks.
App-based OTP and push seems like a reasonable middle ground, short of supplying everyone with FIDO keys. It’s still better than SMS or email - or no second factor at all.