Phone number is the gold standard identifying for third party data collation services.
This is why so many companies demand it.
One solution is a burner phone and burner SIM, for SMS only.
I just change those when I get a new number, its usually just a matter of getting a text confirmation code from them to verify the new number.
I change passwords every year or two. That's really a pain, at this point its somewhere around 30 or so accounts I have to go through and update.
I can kind of see why not allowing 2FA to a number that could be easier to loose, but that's weak argument. Of course they don't want someone from .ru to get a US number with all of the baggage that would entail
There is a simpler/better way and that is to verify you have your email address before allowing you to do a NONCE with B.