There are a number of two factor authenticators which dont use SMS at all. One of the most popular is Google Authenticator, which works with everything from Lastpass, Facebook and Google services (naturally) to Tumblr, Salesforce and Amazon. One scam attempt where SMS verification is concerned is for the attacker to obtain the mobile number, then phone the network claiming the device has been lost. If theyre able to convince the network to forward SMS to their new phone, then they now have access to the bit thats supposed to be more secure.”]
Source: https://blog.malwarebytes.com/cybercrime/2015/12/turn-off-your-two-factor-authentication/

