Yep, I had Google Authenticator enabled. Which makes me wonder how secure Google Authenticator seeds are stored at havelock.
Also, I didn't have country based ip locking enabled, which was stupid, and means that they could have used Tor without any issue.