For those in a similar position, I can recommend Yubikey tokens for good Two Factor Authentication. SMS text messages can be hijacked so, software authenticators are a good option if you don't have a Yubikey.
For password management, Bitwarden and Lastpass have both served me well. Bitwarden is what I use today and it has worked well for me.
Good luck with cleaning up the mess these criminals create.