Had a user at work get his account hijacked due to a phone number spoof. SMS or phone verification is one of, if not the least secure MFA options. Let alone a primary sign in option.
Spoofing a phone number is significantly easier, as is sim jacking. Gaining illegitimate access to your email account requires bypassing your password and potential MFA methods. It’s not even close to the same thing.
There isn’t one reputable security company that won’t tell tell you that SMS authentication is the least secure and you shouldn’t do it if you can avoid it.