Gmail account compromised overnight - mass email campaign sent from my address

This morning I discovered that someone had gained unauthorized access to my Gmail account and disabled my two-factor authentication. When I checked the security settings, I found login activity from someone in the Philippines dating back about a year, which I never noticed before. The attacker sent out dozens of emails from my account before I could regain control. I immediately changed my password and re-enabled 2FA. I’m also seeing login attempts on my LinkedIn profile from the same geographic region, even though my LinkedIn has minimal information. My main concerns are: what additional security measures should I implement, and is there a risk that my personal information was included in those mass emails, or were they likely just spam/phishing messages sent to my contacts? I’m also wondering if the breach could be related to granting permissions to OBS software on my local machine.