I just posted this elsewhere, but here's my take on it, since it shows my reasoning on this whole thing.
The problem with trying to blame someone besides TSR, is that it's becoming increasingly unlikely.
Hijacking people's accounts is not some mystical thing that smart, computer-literate people can magically do. It's very unlikely that these accounts were brute-forced. That just doesn't happen anymore. Password restrictions are strict enough, and sites block IPs for a certain length of time after login attempts. The fact that they got into LJ helps me to think the passwords were known. I said as much when simsecret was hacked, too. So, basically, here are all the alternatives to "someone got ahold of passwords from/via TSR" (and I believe TSR is at fault IF they had a security leak months ago that they never told anyone about OR if someone there is doing all this):
1) Sinthe, Buggybooz, and Thomas are all random morons using something like "password" as their passwords. All these accounts were shown using IPs that trace back to what is probably the same person/computer. Even if you don't believe that Sinthe's case is the same person and it was someone else coincidentally using the same browser on a similar computer with the same IP masking service, you've still got the other commonality there.
2) Sinthe, Buggybooz, and Thomas are all close enough to the same untrustworthy person that they have given out their account information to them.
3) Sinthe, Buggybooz, and Thomas all fell for a phishing scheme and entered their site information at a malicious third-party site. This requires both Sinthe and Buggybooz to have been active at all at TSR sometime recently, and it means the entire community has been too stupid to notice this.
4) Someone is using a cookie-grabber on a malicious third-party website, and these people all had a TSR cookie with an unhashed password, so TSR is still run by idiots. And Sinthe and Buggybooz would have had to been active on the TSR website pretty recently.
Add in the fact that the only people who knew Buggybooz was even complaining about a stolen item were those at TSR and the FA forum at MTS2, and the timing of the attack on Buggy is ridiculously suspect. It also doesn't strike me as a good way to frame TSR, because it doesn't honestly seem BIG enough.
At best, it seems TSR is a terribly insecure site run by morons that should probably be prosecuted and, at worst, TSR is a terribly malicious site run by morons that should probably be prosecuted.