Phishing-resistant MFA
Not all second factors are equal, and the difference is whether the thing can be tricked into helping.
A code from an app or a text can be read out, typed into a fake site and relayed by the attacker to the real one within seconds. It works perfectly, just for somebody else. A phishing-resistant factor, a passkey or a hardware key, is tied to the real website's address and checks it before responding. Shown a convincing fake, it simply does not answer. That is a different kind of protection from a factor that answers whoever asks.
Checked against the primary source.
