I don't know how effective it is, but something I've done on my steam account is also enable the steam family view, meaning if they manage to log in with the username and password, bypass the 2FA, they still need the PIN to bypass the family view before doing anything.Logged in via my phone. Aside from a few spam messages to my friends list, seems ok.
lesson learnt.