It is lucky that you have only lost 10k satoshi, and it is now a good timing to add 2FA to your Google account.
AFAIK, the only (feasible) way you can bypass 2FA is with an aes.json backup or the wallet.dat file itself.
Looks like there is some misunderstanding here.
From your post, it seems to me that you have 2FA on your blockchain.info account, but you don't have 2FA enabled on your google account (everyone can login your google account as long as they have your password).
What I want to say is that, you should have 2FA on your Google Drive account as well.
http://www.google.com/landing/2step/With that, it is less likely to have your old backups on your google drive stolen.
Ah, no I do have 2FA on the Google account, but the
permissions were the culprit - Google shares the wallet files by default when they're put on Drive, which is silly for obvious reasons...even most of my documents I wouldn't want to default share with everyone.