From all of these suggested possibilities, I do admit I saved the seed in my google drive. To access my gmail account though, requires 2FA. Google did not notify me for a remote login etc. I used the same seed since 2017 on the same ledger device.
It's very hard to say for sure, especially without knowing you or being able to physically inspect any logs related to you... But saving a seed in your mail is a big red flag... I did see several people in the past that used this method and lost their money... Same for icloud, witch was even worse...
I'm not saying this is the case for you, but i doubt somebody without physical access to your metadata will actually be able to pinpoint the exact problem and cloud leaks are not that uncommon so they're probably the vulnerability with the highest odds in this case.