She did everything she was told to do and so unsurprising is shocked at what happened.
The tragedy is that nobody is calling out the vacuity of using a text message as an authenticator. Hell, even the MIT alumni association does this and they should definitely know better!
It's going to take someone serious, like the FTC, to force a change in this lazy and dangerously ineffective approach. But TBH I fear that the alternatives that might work for the bulk of the population (who, after all, have other things to do with their lives than become computer security experts) will just move do a different, and equally dangerous point in the option space. Its not like most people can manage a password manager, much less its dynamic key features.
For example choosing a very large third party (like "log in with google"/Apple/Facebook and so on) just allows a different kind of attack to lock you out of everything, likely with no recourse.
I'm struggling to come up with a better second factor for "normal people".
* Email: good if it is different than your login identifier and not tied to something ephemeral like work or school. But how many folks have two email accounts they regularly check.
* Passkeys: tied to a single device, so you need multiple devices. Or you can trust a bigco to sync private keys (!) across devices.
* Social sign-on: has the issues you point out, primarily that it is a single point of failure and the company providing the service doesn't do customer support (typically).
* Paper mail: latency is too high.
* Phone call: subject to same SIM card issues as SMS.
* Questions about identity, such as mother's maiden name: hard to find ones that are secure/private but can be accessed at scale only by "good" actors.
TOTP: hard to get normal folks to adopt.
What am I missing? Am I reluctantly forced to conclude that SMS is better than, or at least on par with, the alternatives?
Cannot count the number of times I have fomatted my phone and had to beg support teams for access to my accounts. I like to use custom ROMs and I cannot afford another phone just for TOTPs. I hate TOTPs. so much.
4x4 matrix: you are challenged with letter/number for row/column and must respond with the matrix entry. Not much better than totp; try to find it on your phone.
photo array: given an array of challenge photographs, select the one you know is your secret photo.
not-so-secret Q&A: what is your mother's maiden name? Name of your first car? Your second wife's third brother's cousin's name?
I've definitely seen photo array as an additional factor in a 3 factor setup, never as the second factor.
In Australia the federal government requires 2FA using SMS in order to sign in to government services.
Yep, it's as brain damaged as that sounds.
And yep, the exact same government is trying to centralise even more data and hook it up into this system.
They literally do not listen to anyone, and just do whatever the hell they want. :(