It’s indeed true, hackers always do find means to get the job done even with 2FA in place. That’s where, many sites that use 2FA today no longer prefer the email options to it. Many uses Google authenticator app given that, emails are easily hacked and once that is out of the way, it’s always a straight way through to account hacks and you’ve got little to do about it if you don’t get to noticed on the mails.
Account security is not meant for the casino alone rather securing your account involves both party although personal data are protected by the casino. Not all 2FA process are the same and the email process is still required by some site along side google authenticator app for example getting a google Authenticator app still requires customer email. Both process sound more better compared to one meanwhile account hack only happen when a person is not conscious about their account, exposing email address can as well get anyone in a wrong situation.
So that means we should never reveal the email that contains our private information to others. We can create an email for business, relations, gambling sites accounts, and for the Authenticator app. So all of that will not be related to our main emails because we split all things into different emails. We don't share the email for Google Authenticator or other Authenticator apps if the app requires customer email, because that contains our sensitive information on all sites we use. We share the email for the right reason so we don't have to worry about bad things.
We can reveal only our public email which is on where they can contact us if they need something, like email to use to reach us out.
But for other important matters like on where our important accounts on which we do financial deals then we make all of it private and away from public eye.
Also I think separate each accounts and set up different password is important so that we will not fall down easily if it happens that there's some exploits or hacking that might affect us. Lots of ways on how we can make our account safe. Its just we should stop being lazy to do this things since if we prioritize safety for sure nothing bad will happen on our accounts.