I have a number of comments on this. I don't suppose anyone will read them this far down the thread, but ah well. Firstly - the password "database" that may have been stolen, would have been md5 encrypted. Which means that it still has to be brute forced to get anything from it. So if you use a secure password (with numbers, other caracters, captials and lowercase) then most likely it'd take far too long to brute force, so it's all good. Secondly, if you're using a different password for all your logins in different sites (as you should be) then there's no problem. Thirdly, connections to this site are not protected by SSL (eg. https://) so with relative ease, anyone can spy on the data you send to and from the website. So you're really placing too much importance on this database. This is a runescape fansite forum, not an online bank. Tip.it and Jagex both reccomend you use secure passwords and don't re-use them accross sites, so really you've got no excuse if you've been so stupid.