I still dont see why SE doesnt add one of those verification email code things like Rift had.

Any account that doesnt have the security authenticator installed needs to input a code sent by SE to their email if they try to log in from a different (and especially foreign) IP address. If they dont do it then chat is disabled, and no access to banks or anything an RMT could want. If you have one of those PPPoE connections that change frequently (they still do those?) and it bothers you then get the authenticator. Honestly, this should be standard stuff.