Well, a VPN won't protect you from anything but IP locating. It's not going to protect your passwords. The only thing that protects passwords is your diligence. No matter what kind of security you use your password is stored at the server you use it on so if they get hacked your password is compromised. There is nothing you can do about THAT happening, but you CAN be diligent about your passwords.

I just counted and I have 175 different places where I need a logon. No two have a combination of the same username and password. I may use "password" (obviously not THAT) on more than one place but it is also on a different email address, and I have 27 of those. All with different passwords. Those are in a text file on my computer that is password protected (and good luck random guessing THAT password - it's based on a foreign word and contains a number that only means something to me.) I also take the computer with that file off the network when I am not using it.

Even with all of that, consider this. If my logon here is username is EddieIsaRoyalPITA and the password is 525600Minutes, and someone manages to get their authentication file, what could I have do to prevent that? Even if their user auth files were stolen they wouldn't know it. The info may not be sold immediately, either. Users are on the losing end of every aspect of this. All we can do to stay safe is all we can do to stay safe. My KEY passwords get changed every 60 days, too. Be particularly careful with your email password. Change it every 60 days. A skilled hacker can do this. Change the email password, email you a file with a time bomb in it, access your email, execute the time bomb, and then create a snapshot of your computer that would allow him to order things masquerading as your computer that looks like it came from your chair. Order them to be delivered to another address, then call in a redirect to send it elsewhere, so the original address has nothing to do with his location. And you get the bill. Even if they don't CHANGE your email password, they can still log in with it, do their damage, delete the email, delete it from trash, and you may never know it ever existed. And a VPN will NOT protect you from that. A top black hat hacker doesn't need your IP to hurt you.

Disclaimer: Don't ask me how I know about any of that.