https://proton.me/blog/google-data-breach-gmail-warning
The hack exposed a systemic weakness in Google's Salesforce. It immediately captured all of the customers / client's information for every company that uses Salesforce (just about every company out there that uses e-commerce).
The hackers can generate phising emails that come from actual, validated Google accounts. Telling you that your password has been compromised and then asking you to choose a new one (twice), is as old as the hills without 2FA, but millions of people still fall for it -
One of many reasons why I don't discuss any "hobby" related items with anybody using a GMail account.