From what I can see in the audit log, the only people to access are the other two admin. Admin 1 did everything up until changing the password, logging out and logging in. The only thing I can see apart from me logging in later, is a ‘txt add’ relating to a DNS record for bluelight.org. Here is the audit log, I’ve tried to make it clearer and removed the account name.
Admin 3/me:
Jan 16, 2019
Login
Jan 16, 2019
Logout
Our account login here
Account
Jan 16, 2019
Login
Our account login here
Account
Jan 16, 2019
Deployed
Cloudflare
Jan 16, 2019
Ordered
Cloudflare
Admin 3? This has an IP by was done by domain “bluelight.org” rather than “account”. There is no record of the IP logging in:
Jan 16, 2019
TXT add
Our account login here
bluelight.org
Jan 16, 2019
Created
Cloudflare
Jan 16, 2019
Created
Cloudflare
Jan 16, 2019
Nameservers confirmed
Our account login here
Jan 16, 2019
Crypto change setting
Our account login here
Admin 1:
Jan 16, 2019
Login
Our account login here
Account
Jan 16, 2019
Logout
Our account login here
Account
Jan 16, 2019
Change lostpass
Our account login here
Account
Jan 16, 2019
Logout
Our account login here
Account
Jan 16, 2019
Zone reset check
Our account login here
Account