In my experience preaching this same thing to many users at work and just personal friends, they won’t change their ways. Because “omg not another password to remember” and “that’s too much work to login just to get a password”.
I’ve just stopped trying to educate people at this point. That’s on them when their info gets leaked or accounts drained.
Yup, they couldnt care less about any 2FA. But then they get the surprised Pikachu face when they get breached after being phished lol.