That reminds me of the effectiveness of texting codes as MFA, when the password can also be reset by texting a code...
Those services just have SFA (Single Factor Authentication): the cell phone number (which can be stolen remotely by social engineering).