SMS based OTP has been known to be unreliable way to authenticate someone because exactly this type of social engineering hacks.
All software providers and the industry should ban SMS based OTPs as a standard practice. Either leapfrogging to a Passkey implementation or just time based OTPs.