Did not have 2FA, Fucked up

. Attacker gained access to email and reset my exchange password. Pretty sure that makes me screwed.
The question is, how did they got access to your email? Weak password? weak recovery words? Was your OS compromised with some malware that siphoned out your password to attackers?
I know someone who lost 6 figures with an even worse mistake, and there have been posts in this forum of people losing 7 figures, so yeah it could have been worse. At least you were smart enough to keep cold wallets unlike the aforementioned examples...