Also: maybe the person who is causing this problem is using the very popular free FTP program FileZilla and stores the passwords in the program (by adding the site in the Site Manager). FileZilla appears to be vulnerable to certain malware being able read the contents of the password file and sending it to someone else, who then sells the passes to people who do stuff like the above. The safest way to use FileZilla on Windows, but maybe also other platforms, is to not store the passwords, but to use Quick Connect. It's a little more work, but much safer.
"Yes, there was a spambot some time ago on these forums." - aa