Happened to me yesterday (I don't mean the ID spoof / whitelist thing, but I was hacked). I noticed in my browser history some entries that are not from me, something with paypal itunes gifts. Luckily he was unsuccessful, I didn't lose any money. I just hope that's all he did ... I had the logs disabled, so I don't really know.
Actually, I think the attacker was still logged in: in the info panel at the bottom right, I saw my TeamViewer name, but in this case, it wasn't followed by a 9-digit ID in brackets like usual, but by "(1) (0)". Not sure what that means.
I uninstalled TeamViewer from all devices. I'll use RDP and VNC with router port forwarding for now.
Whitelisting doesn't make any sense to me, since I want to access my home network from new devices too. But the 'unattended access' option was enabled, my password wasn't very complex or long, and I didn't notice the two factor authentication option either, so I guess it was in part my own fault. When I started using and configuring TeamViewer, the main priority was not security but to make things work ... maybe I'll use TeamViewer again, but then I'll definitely be more careful.