Great question. There is an important difference:
A standard phone call places a burden on malicious listening software to decode raw audio into computer parseable text, before it's useful to an attacker. Computers are getting to be pretty good at this, but it's still kinda expensive, relative to the massive amounts of hours of calls that one might need to snoop and parse to get a good tidbit worth stealing.
Fax, being already raw image data, incurs a much lower cost of doing ocular character recognition (OCR).
So an attacker can pay a lot for expensive voice recognition to pull an SSN off a voice call, or pay far less to pull an SSN out of a fax using OCR.
Attackers like both, if they're motivated and well financed. But an underfunded or lazy attacker is going to prefer to listen in on the fax line.
Note that this is a reversal of previous security preferences, when the snooping would have usually been done by a bored human. Bored humans are great at parsing audio calls, and have no idea what they've overheard in a (bleep boop beepity boop) fax call.
This has been: "Cybersecurity insights that make us all sleep a bit more poorly."