Implement Multi Factor Authentication on the login page please.
Ideally OTP based dso we can use Google Authenticator or MS Auth applications, but even just a basic email based MFA would be sufficient to start with.