Whatever you still have access to (again, from cache, existing browser that's still logged in, etc), start making backups - screenshots, etc.
Then it would be been impossible to login. Did you use a password that was leaked? If yes - may be they logged in - and you would have got a 'notification' on your phone to allow them. And you perhaps said yes to that remote login.
She is still logged into her account on the laptop, so she can see things, but can't make any changes (they require a password she no longer has since the attacker changed it). We saw what the attacker changed the recovery info to their email / phone as well. So recovery options aren't working. She is trying to pass their email/phone along to some form of law enforcement.
This doesn't make sense; the attacker changed all of her account information but didn't click "log out of all other locations"?