Have to amend my statement...if the attacker can intercept the SMS in real time, then it is an effective attack:
1. Attacker knows victim's phone number and attempts login
2. Attacker intercepts SMS as it is sent to victim
3. Attacker completes their login process with the SMS code