I have found and installed a free captcha module now. Hope this will protect the existing customer accounts against being spied upon by the attacker.
https://github.com/nenes25/eicaptcha/releases/tag/2.0.4
Seems to work, at least it didn't break the account creation process for humans - hope I can follow the advice and just forget about this issue.
Cheers