That is why, whenever you create an exchange account, you should ensure a few things:
- Set up email access on more than one device! This ensures you to receive a notification, if a login attempt is from outside your usual location.
- Always enable 2FA! I am sure that most exchanges support this by now. This involves using more than just a standard email code. You can use certain methods.
2FA activation for your exchange account and your email is a very good security advice but it's not enough. It's second layer security protection so it must be installed and activated on a second device, that is different than a device you log in your exchange account and email account.
Many people install and store everything on one device, log in every accounts on one device, with such practice, 2FA won't be able to secure their exchange account and fund.
Such as: like Google Authenticator, a specific PIN, phone number notifications, or other options. It will probably provide a higher level of security. Better than relying solely on email notifications.
Google Authenticator is not a good 2FA application.
It's close source.
Years ago, it launched a feature to allow user backup their 2FA code in cloud storage.
There are other choices, better too, like open source 2FA.
https://getaegis.app/