I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then…
I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.
I don’t see how this happens if you use strong passwords without reuse.