I took three steps against this happening:
1) Not providing phone number for 2FA. Never.
2) Using multiple (3 pcs.) physical keys for 2FA (like Yubikey and similar). Authentication app is an alternative for one choice of 2FA (but not the sole one!)
3) Only using a limited set of Google functionality. Use for secondary purposes mostly.
Well, the last one is mainly to mitigate the consequences if happens anyway, for other reasons too (like with that poor guy who made picture of his own naked baby for a remote diagnostics with his doctor and the Google locked him out for months - and still counting at the time of the article - for child pornography)