Change your shit asap. Anyone who has access to it can theoretically auth as you on any site or product that uses that 2fa setup. They would still need to have your underlying credentials that would initiate the 2fa protocol exchange anyway, but if they have access to your underlying 2fa secret, its not too far fetched to believe they may have other credentials potentially, depending on how you’ve secured the access and where you store your credentials. To be safe and not paranoid, it’s best to just do a root trust rotation and cycle the underlying auth creds
The research cost recovery line they often yap about is bullshit itself though. The overwhelming majority of pharma research like the one involved here is subsidized through taxpayer dollars already, and they get tax incentives and write offs for failed research. If we had a sane, working government we could nationalize all life saving medications funded by public money while still allowing the inventors to enjoy some (reasonable) economic benefits from the research