Only real basic things you can do, dont use your primary cell/emails as 2FA backup. Amazed theres no company offering security enabled sms enabled numbers via a webpage to plug the sms hole.
And if you use your primary cell for 2fa, call your carrier and put a no-transfer lock on your account. This is how the bitcoin hacks happen.
Also, google has titan keys, they ignore them for 2FA also. Kinda mornic.
Alongside this, they sometimes send an SMS OTP to verify it's you making a purchase. I don't want PayPal anywhere near my SMS inbox. It's so backwards.