Its a shame that the majority of accounts used to spam RMT sites are hacked. Most players that loose their accounts to hackers basically give their passwords away tho. Either they fall pray to an email scam and reply with login info, log into a fake website, or use the same password for everything including fan websites that are easily hackable.
Fan websites are fun, and offer a lot of content. However, when you sign up for these websites NEVER use important passwords. Even if the website owner is completely legit, these sites often do not have adequate security making it very easy to gain access to the websites database of user names and passwords. The hacker simply uses a bot to try logging in with the same username and pass.
As for the email scams. I hate to sound rude but if ppl are still falling for this kind of stuff I feel really bad for them. Even if an email looks totally legit there is NEVER a need to reply to it or follow links in it. Always use your web browser and manually type in the web address. (not the one inside the email, the one to the legit site :P)
A security token will definitely help... but if you ever lost it good luck getting a hold of SE's customer service department.
