Instead of anyone whining about their accounts getting hacked, take preventative action so this will not occur!
Probably the most common issues with passwords for accounts is they are too weak. Here are a few things to follow to make sure your password is stronger than the average noob's password:
1. Make sure to have at least three of the following: Capital letter, lowercase letter, symbol, number.
2. Make sure the word "password" in any form is NOT in your password. If it is, you fail and change it NOW!
3. Make sure your password is not the same as your user name. It may sound funny, but I'm sure there are plenty of people that do it.
4. Do not give your password out. Even if someone is your "friend", they can easily ruin your reputation on this website, or hack your bank account, sell your WoW account to Chinese gold farmers, etc.
5. Make sure your password is at least 8 characters long.
Now here is an example of what a strong password coule be: Examp13#0n3
The above password has capital 'E', lower case letters are 'xamp' and the 'n' second to last. Numbers are '13', '0', and '3'. Symbol is '#'.
Is the above password example a strong password...? Yes, but since it is posted in a public blog, you should not use it.
This is not a hard thing. If I hear of anyone whining their account got hacked on this site, I will ban the account to give a nice 24 hour period in which the password can be changed.
Passwords are encrypted in the database with SHA1, which is a one-way encryption. That helps security in case someone happens to get ahold of the server's master password, but strong passwords are still a must.
Even though I can not decrypt any passwords, I did try comparing some known values against them by encrypting them the same direction. Here's what I found a few months ago:
Around 75 members had either "password" or "Password" as the account password. Around 25 more had the username as the password. I messaged every one of those members, requesting a password change. Most of them replied back with snobbish comments like "what of I don't want to?" I have no sympathy for an account that gets "hacked" and wreaks havok on the accounts of other members. It will be a perma-ban, no questions asked.