Yep, I had Google Authenticator enabled. Which makes me wonder how secure Google Authenticator seeds are stored at havelock.
Also, I didn't have country based ip locking enabled, which was stupid, and means that they could have used Tor without any issue.
This is really strange. I don't think you can get Google Authenticator seeds so easily.
You must have a keyloger or it could be a man-in-the-middle attack.
Please provide us more information about what happened.
Everyone check if you have this enabled :

