SMS-based two-factor authentication (2FA) is considered the most insecure method of 2FA due to several technical vulnerabilities that can be exploited by attackers.
One of the primary vulnerabilities of SMS-based 2FA is that SMS messages are transmitted in cleartext over the cellular network, which means that they can be intercepted