I used only LTE from my mobile operator (TELE-2). We doesn't have any wifi networks in our place, so far away from the city (60km).
These days I was trying to understand how this happened. But all the known cases come down to is downloading the Electrum application from fake sites or entering a seed phrase in third-party applications. I didn’t do either one. the question is still open for me. It would be great if there were logs in the electrum, in which you could see from which application the transaction was made or any data about the device. but as I understand it is impossible.