If you gave your login info to a phishing site, then, yes, the person could log into your account and change the password, and the PIN. SR will never ask you for your PIN at login. Always make sure you are accessing SR from the correct url: silkroadvb5piz3r.onion EDIT: At this point, you'll need to send SR Support a message from your new account. Be sure to give them as much info as you can to prove the account is yours - including the last btc address you used and the last btc deposit you made. Here's a direct link to sending them a message: http://silkroadvb5piz3r.onion/messages/send_message/104259