She didn't have 2FA set up, only a password which is as she found out is NOT a good idea but I didn't realise and I don't like to be too interfering. She had her email account hacked and they managed to order some stuff from shein and another site totalling £122 but I did manage to cancel one of the shein orders before it was dispatched.
She has since had the money refunded but looking at some of the emails they tried to order over £1000 worth of stuff but the orders have been stopped thank god. This has really worried her and I've got her to change a load of her passwords to much stronger passwords.
The only good thing to have come out of this is it has made us both much more security conscious and I am now updateing ALL my passwords.
Just as a side note a got a email pretending to be from my bank asking me to update my phone number and I normally spot these scams a mile off but this one had my full name and part of my postcode and it really did look genuine, fortunately I didn't proceed to update the details and it was only some time after I got the email I thought 'hold on I'm still getting texts from the bank so they must have my correct phone number '. I have since reported that email as phishing.