1st, there is a lockout still for the wrong password/secondary password.
2nd, these "hackers" have access to the database, because they have the primary and secondary password for so many different accounts AND had access to a gm account.
3rd, If mutliboxing is actually a violation of the tos(a claim made by a gm), frogster would be well within bounds to place a simple program to block access for an account from any ip other than the one registered.