I used macOS/Chrome back in 2017. I definitely could have been phished then, or used a compromised extension.
Or does LP shoot an email if it detects a suspicious geo-IP login before the 2FA prompt?
Once the IP is approved (you have to follow a link from the email), then you login again with the correct password and then get the 2FA prompt.
Or does LP shoot an email if it detects a suspicious geo-IP login before the 2FA prompt?