Well, who can then?
My password was fairly strong, I do not share my account, it's a unique password, ... So I don't really see how they could have done it beside brute force which should be easy to block; suspend the account after 10 unsuccessful tries let say.
I'm happy they have the authentification process now, but only learn about it while browsing the forum to find a solution to my situation.
What are my options?