It is always very difficult to admit that you could have avoided theft if you had been vigilant in advance. But it happens, you only have to learn from your mistakes.
I don’t want to be boring saying it that it could be done this way, or so. But in this case, it is really a mistake to have mail that does multiple tasks. That is, it has to do with finance and the forum.
Regarding 2FA it's always a two edged sword giving a false sense of security: there is no security advantage setting up a 2FA on your mobile while you access your website with the very same mobile. 2FA should be enabled, for critical services, on a different mobile or computer the one you are using to access such service.
Now the question. If I have a very good password in my mail that is difficult to crack, and I have 2FA, if I log in from another IP, I receive SMS notifications, isn't that enough? And also the mail that is tied to the forum is not used anywhere else.