Guys, I'll add one more important thing :) Right after changing your passwords, definitely check your login history and active sessions - usually there's an option for this in your account settings. On Yandex, Google, social media - check everywhere to see what devices and IP addresses were used to log in. If you spot any suspicious logins, terminate all active sessions. And yeah, if any services have payment methods linked or documents stored there - that's critical stuff, hackers go after that first.
Here's another tip from personal experience - call your bank not just the support line, but actually visit a branch. Better to check in person that everything's okay with your account, lift any blocks if needed, and reconfirm your number. Sometimes there are inaccuracies over the phone :) Ask the bank for a statement of all transactions from the last few days, maybe something got through there.
And most importantly - change your number or reconfirm it from your own device on all the services you use. Two-factor auth - it's protection, but only if the number is actually under your control. Switch to a new number if you can, and you can ask your carrier to close the old one or freeze it so the attacker can't do anything with it.