Quick, someone cook up a ruby script to generate a million or so bogus logins to swamp any real logins they might have gotten so far. Pass it around.
If would be an active spam fighting solution instead of all the 'turn the other cheek' solutions that are popular right now...
Right now I'm guessing that most of the hits he gets are legit from fooled users. If we were somehow able to break the model by making 99.9% of all of the info gathered worthless, they might stop altogether. In any case it would provide some cover for the people who were fooled and supplied legit creds to have a million or so bogus ones surrounding them.