It would be more likely that the customer's computer has been infected and the person doing this is using a keylogger to get the login info. Suggest having the customer do a virus scan on their computer using whatever anti virus software they have, as well as an online scan:
Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro USA
Also make sure all scripts on the website are up to date.