What else do I need to do.
You need to establish a new email address just for stock, and a new separate one for Paypal or whatever you use. I use yet another for banking. I then have those addresses all forwarded to my main address so I see any unusual activity. These addresses are all registered under a private domain I own for which no live website exists.
Never use either of your commerce/business addresses for posting comments on any blog or for registering on any forum, flickr, twitter or facebook or any other social media. I use a junk address for forums etc that I never even check. Ever. If you used your main address on facebook my guess would be that is where the hack occurred.
If you buy or sell on fleabay use a whole separate address for that as well. Ebay vendors have been known to empty out paypal accounts depending on where you purchase. My sister got her account emptied after buying some some computer gaming thing there from a small vendor. This was probably about 4 yrs ago before they tightened things up a bit.
The above sounds hard buy it it really isn't unless your are extremely active with the social media or are nervously checking on everything every minute of the day.
As far as using a google address, sorry to say good luck on that. Google is in the business these days of harvesting as much data as possible on everyone. When they kept demanding my cell phone number to keep an account "secure" I dropped all the google addresses except for a junk account.
Good luck and hope this helps you out a bit.
And just as a note, I would post as little information as possible here on the forum regarding any ongoing processes in attempts to resolve the problem. Even though you may feel that it may help others, you will only expose more info about yourself. A simple, "everything is ok now" will be good enough.