I'd like to open a discussion about best practices for hobby security. This is a topic I think about often. One thing that I see as a weak link is the system of trusted phones. Once a phone number is trusted, no one (me included, usually) gives it much thought. Perhaps they should be re-verified periodically but realistically I don't think that will happen.
I always try to keep something in mind about each provider that only she and I would know, in case I have any doubt and need her to prove who she is. It may seem overly paranoid but I've actually had someone pose as a provider I know before (in email, though - her email got hacked) and very nearly had me convinced due to perfect mimicry of her writing style.
The question doesn't even have to be about something that happened. It could also be about something that didn't happen that the provider would be well aware didn't happen but an impersonator wouldn't be.
It's on my mind today because a provider reached out from a new phone number and said it was her. I think it is her, but I'm awaiting the response to my verification question to know for sure.
I will say I think it's better form for clients and providers alike to reach out from somewhere else (here, p411, existing trusted number) for notification rather than just the new number itself.