I started to read through this topic, got to page 10, then skipped to now. I left off where Tom is going to borrow a key to give to Poi in return for his stuff. What happened inbetween?
Also, I doubt Poi is a script kiddy at all. If Tom ever registered at Poi's forum, then Poi probably just viewed his password, the tried it here. And assuming Tom uses the same passwords for everything, he was able to get a hold of his forum account and his email. His email would contain the rest of Tom's passwords and account details.
And just to give Poi the benefit of the doubt, if he really did "hack" him, he probably just used a keylogger or just brute-forced his way in.
What Tom should do is contact his email company to see if he can get it back, as that is probably the most important. He could also try to do the "Recover Forgotten Password" to get it back. From there, he could just do the Recovery for his password on all of his other thing. As for his BL key, he could try to contact Badspot to get the activation code changed.
Sorry if this is all irrelevant because of new information, but that's my thoughts on the matter.