2. Change your own email password (when did you last do that!!) NOW...
Yes, thanks for the prompt Alistair. I've changed mine now. I hadn't received anything from Rich and have no evidence of compromise, but security standards have changed a lot since I first set it.
My suggestion to anyone who has been hacked would be to create an entirely new email address, obviously with a different password, and to go through changing the email address in all the accounts that they regularly use. I have several email addresses and now use one only for logins that are important for security, others I use for unimportant sites that may be less secure. That way there is less chance of breeched security spilling to important accounts.
I've mentioned this before but worth repeating. If you register your own domain you effectively get as many email addresses as you like. I use a unique address with an auto-generated password for every login I create. I have a "catchall" which redirects the addresses to my gmail account, but if any of them is compromised I can disable that particular email through the control panel.
I'll admit it requires some technical knowledge to set up, but if you have the ability, it's well worth doing. I pay £8.99 a year for a .UK domain and £20 p.a. for the hosting, which I consider much better value than a VPN or Anti-Virus package.