She did everything she was told to do and so unsurprising is shocked at what happened.
The tragedy is that nobody is calling out the vacuity of using a text message as an authenticator. Hell, even the MIT alumni association does this and they should definitely know better!
It's going to take someone serious, like the FTC, to force a change in this lazy and dangerously ineffective approach. But TBH I fear that the alternatives that might work for the bulk of the population (who, after all, have other things to do with their lives than become computer security experts) will just move do a different, and equally dangerous point in the option space. Its not like most people can manage a password manager, much less its dynamic key features.
For example choosing a very large third party (like "log in with google"/Apple/Facebook and so on) just allows a different kind of attack to lock you out of everything, likely with no recourse.