Brutal situation—sorry you’re dealing with it. A playbook that’s worked for folks: assemble “hard” proofs that tie you to the account and ask GitHub Support for human identity review, not automated 2FA reset. Think: old phone number ownership, email at a domain you control, past billing receipts (Sponsors/Actions/Marketplace), SSH public key or GPG signature fingerprints from your commits, WHOIS matching your name, and ecosystem attestations (RubyGems maintainers confirming you own those packages). Put all that in one concise ticket and request escalation.
In parallel, talk to RubyGems support about stewarding the gems if GitHub recovery stalls. They can add/transfer ownership with credible verification, so users aren’t stuck. Worst case, spin up a new GitHub, mirror the repos, and note the account transition in README/changelogs—plus a release on RubyGems pointing to the new home. Not ideal, but it keeps your users safe and the project alive while you push on account recovery.