Read all about it here. I've changed all my stuff, I should be safe, but I'm pretty sick over the whole deal. But anyway, according to my sister-in-law, there was a google leak through Niantic, aka the Pokemon Go company. I'm not sure how far I believe that, as I have no sources, but if you have Pokemon Go, I'd check your stuff just in case. Stay safe~
I quick search does confirm that there are reports of info leaks and since the program had/has access to personal information on the other parts of your phone like logins so it does add up. Just hope you didn't do banking or anything via that account.
Well, we all knew it was a problem that needed to be looked into, but hopefully now they'll actually try and take action to increase their security if you're signing on with google. I haven't seen anything wrong with mine, but I changed all my info as well. Maybe i'll also switch to using a pokemon website account...
It's weird that Pokemon Go would have issues. The way it should work is that you sign into Google yourself, and then Google talks to Pokemon Go and goes "Yep, that's them." Pokemon Go would never see your password, only the email address. But yeah, email hacking is scary no matter how it happened. For gmail people I recommend turning on 2-factor authentication. Basically to long in you need to use your password and another password from your phone that changes constantly. Makes logging in a bit of a pain since you need to pull out your phone to grab the changing password, but it makes hacking you insanely harder. EDIT: Well I was suggesting something you already did. So I feel silly now. I read things good.
I don't think you've overreacted at all: email accounts like the one you have now are in such an important state these days. It's a good thing you got it fixed as soon as you did, and good thinking adding the verification stuff.
There's that, and you can also change it to where it sends you a verification option that has you unlock your phone, so if they don't have your phone, they won't be able to get on either way
Honestly, phone verification is something I should've done ages ago. I have it for my twitter, and I have no idea why I never thought to do it for my email and google accounts. It sucks that it took something like this to make it happen, but I'll definitely be more careful from now on. I actually spent most of the day very sick because of what happened (to the point that I called in sick to work), but I'm feeling much better now. I anticipate that I'll be back to 100% tomorrow.