Scary situation there! I thankfully switched mine over months ago once I realized the vulnerability. I think as well if you create an account that's an alt through a service like PeakD you are set as the recovery account. I haven't made an alt in a while but I think that's how it works.
Glad you were able to get it squared away!
Pretty sure that's right. Accounts I created for others using resource credits etc have the account creator set as recovery account, which is sensible. The 'steem' issue applies to older accounts, AFAIK those created by Stinc.
Good for you for acting on this realisation - it was my lack of action that almost cost me dear.
Thanks for stopping by and commenting :)