I did nearly continue the deliberate poor grammar by arguing that of course I wasn't 'defrauded' - that would mean that someone had removed the fraud!The crime is called fraud, so it made sense when the OP said they got frauded. Didn't realise it's actually defrauded!

Regarding the 'how it happened' - the fraud people seemed singularly uninterested in the question as far as I could tell. Maybe it costs them more to spend the time trying to investigate than its worth to them?
Not so much intercepted, but it's possible someone can clone your SIM, and they don't need access to your phone to do it.
I only use mobile 2fa for stuff I don't care about.
Password managers and my main Google/Microsoft accounts are secured with a pair of Yubico FIDO keys, and printed and stashed recovery codes. Definitely do not use SMS/phone for securing password managers and the like.
"All in Albania" is the name of my new prog-rock-classical-metal-fairy-powerpop band with our new album landing this fall.
Use a virtual card and something like PayPal, never putting card details in.
*eye twitch* Shouldn't it be 'defrauded'?
What's the difference between a virtual card and a physical card? Are virtual cards more secure?I got fraud attempts for weeks after a New York trip. The only place I didn't use a virtual card was the lovel Hyatt hotel we stayed in so GG, skimming my details, very nice of the staff.
Cancel card. Turn of all features you don't need. Move on.
Virtual cards use a random number each time so your actual number is never exposed.What's the difference between a virtual card and a physical card? Are virtual cards more secure?
And by 'virtual' do you mean something like Google wallet?
So I replied to confirm they're not mine, but they are not open until tomorrow, when I will get a call. Presumably they'll have to replace the card.
Just a heads up, when there's an issue, both the CC issuer and PP may argue the other is liable, and consequently neither pays out if there's an issue. I think I read that on here from a member who had this issue, not sure it ever got resolved. Which thread is anyone's guess.
I don't think anything is really fully secure. It's getting increasingly a PITA to keep up with tech.