In more detail
The factors are something you know (password), something you have (phone, hardware key) and something you are (fingerprint, face). A stolen password alone is then not enough. App-generated one-time codes (TOTP) beat SMS codes, which can be intercepted; hardware keys and passkeys also resist Phishing. Try a one-time code generator with the TOTP Generator.