An even more shocking example is Transferwise, supposedly a cutting-edge star of the "fintech" scene. They use SMS-based codes, a wildly insecure form of OTP. Over a thousand employees and they cannot even implement some sort of app-based TOTP (such as Google Authenticator) to protect their clients' money.