Looking at that Twillio report as well as this article it appears that users are able to believe that security related messages will be sent to them by a channel that the business does not control, SMS.
There appears to be a need to establish a secure channel for such messages and well defined processes for expiry (or not) and reset of passwords, that the users are trained to recognise those and report any that fall outside them and that the training is reinforced, not only by repetition but also by tests with fake phishing programmes.
These attempts are succeeding because there are gaps in the users' knowledge of what to expect by way of genuine communication so close up those gaps.