Thanks for checking in your test environment as well, @jpc Nice to know that I am not the only one here that thinks this is a problem. I opened cases with support but who knows where it goes from there.
@jpc, maybe if you also report this to tech support, they will understand the urgency to this. It really makes me uneasy that hacker with stolen passwords, can unroll their phones into MFA.