It's amazing that an account under 2FA in Mt.gox can be hacked. This guy found his money withdrawn on May 31, 2013. Someone changed his password and cancelled all 2FA in Security Center. He says he didn't use his mobile phone to get on Mt.gox. How did the hacker get his private key of 2FA??
It's so terrible which means the 2FA maybe not safe.
Link to this post:https://bitcointalk.org/index.php?topic=221098.0
I wonder if that it why you also have the option to 2FA the ability to change the security settings. Which is the 3rd step.