It sounds like his personal contact details are entirely separate from his business ones. I don't believe they should ever be using personal details to contact a business.
Even if he did provide them his phone number. In many places, that data may only be used for the purpose for which it was given. If they request a phone number for 2FA and then use it to contact you it could absolutely be considered illegal.