As far as I know, cancelling then reinstating the account is the only way you're going to get the character logged out (hopefully before it gets nailed for botting) Even though this is extreme and may cost a bit, it will save a ton of time and effort trying to get a rollback, or dealing with a permaban.

Once you have control of the account, please realize that even though it's crappy and unfair, there are steps you have to take these days to protect yourself. Make an email and password that you only ever use for FF14, and never at another websight, and at the very least use the smart phone app, if not the security key. I've been hacked myself in ffxi ( I am also disabled and understand how much of a blow losing an account can be for us) so I feel bad for your GF. But if after getting hacked you don't take the steps to secure yourself, you have nobody to blame but yourself when it happens again.