First of all thank you so much for taking your time to read and respond. I was out with the family all day Saturday... my apologies for not getting back sooner.
I agree that malware is most likely not involved. I realize this is always an everpresent concern though...
Yes, the addresses all start with 1. The address it was sent to starts with 1. And all the addresses generated by the Electrum Wallet from the seed started with 1 as well.
I did try Derivation paths m/44'/0'/1', m/44'/0'/2', m/44'/0'/3'. No luck. All empty.
I'm planning to look at iancoleman.io's website but have not had the time yet. I understand I would want to download it and use it offline. No worries there.
I have been telling Electrum that it is a BIP39 seed. I also connected the trezor to electrum and let it create a hardware wallet with the connected trezor. I get the same result. Empty wallet but full of all the previous tx's that it showed in the restored wallet with the trezor's bip39 seed imported.
I could not figure out how to have Electrum "detect existing accounts"? I am using version 4.1.5. I googled and read the wallet documentation. I could not find anything along that line. If you have any more information on this I would be interested.
So I did text my sister regarding the statement she made about them "seeing" the coins at first on the trezor before they disappeared completely. This was her response...
When you sent it, we could see the 3 coins in a legacy wallet that was greyed out. We couldn't open it. Recently, when we were collectively trying to get into the trezor without our pin, we reset the firmware. We finally found the pin, but by then the firmware had already been reset. Since then, we have never been able to see it on the trezor. But before we reset the firmware, we could see the coins on the trezor.
This is very interesting to me and gives me hope that the address really does belong to their seed phrase. They are very certain they acquired the address they sent me FROM the Trezor... They just can't remember if it was before or after they changed their seed phrase. I do have both seeds from them. Perhaps I should try all the things I just tried above with the first seed phrase?I also created a "Watching only wallet" in electrum and put the address in it. Of course Electrum shows the bitcoin on the address. I realize this is nothing earth shaking. But wondered if I did derive the private key from the seed if I could "add" that to the watching only wallet to enable me to send the bitcoin out of it? I might experiment with a small amount of bitcoin of my own. Create a wallet. Move a small amount of bitcoin to it. Then open a watching only wallet. Create a private key from the mnemonic that I got from the first wallet and see if I could send coin out of my watching only wallet with that key? I'll let you know how the experiment goes.
Again thank you so much! If anyone has any other ideas, I am all ears. We are talking a significant amount although I suppose that is subjective

But more then the amount I personally am more vested in understanding what/how it happened and how to retrieve it. I may only check this once a day but don't take that as me not being interested. I just have a lot going on in my life as I am sure most of you can relate to.
Cheers.
Kresp