The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?
By taking advantage of Randy's business in a way that will send a message to Randy to let him sort it out.
Once had a client who though they were being clever using a competitors email domain in order to sent a signal of quality and fool prospective customers. The competitor who owned the domain just spun up the associated email addresses and then proceeded to login to all their services and delete them using password resets and email auth.
You used to see it a lot with hotlinking images back in the day, you'd ask a service to stop using a URL and they wouldn't. You then update the image to something offensive and the URL is suddenly removed from their site.
TOTP is portable and can be backed up.
I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.
https://www.cbsnews.com/news/ted-kennedys-airport-adventure/