If the credentials are type on a computer, I would say the most likely scenario is the computer is compromised, a virus.
Make a backup, format the system and start from scratch.
I would recommend Ubuntu instead of Windows. Blocking all ports for incoming connections is very easy on Ubuntu with the ufw command. Not so easy on Windows.