Thanks for the reminder I go this message earlier today and forgot to rotate things.
Wasn't too terribly worried about it since I had 2FA enabled already, but rotating both the TOTP secret and the password isn't a bad idea.
As for paranoia... people around here still click on links in emails? I go to all websites that require a login manually, I never click links on anything if at all possible.