I work in IT at a university, therefore I get to see this sort of thing happen far too often. My suggestion is to use a pass-phrase instead of just a single string of characters. It's much harder to break.
A friend of mine discovered a near-duplicate account of his own, complete with his pics, that he did not create. Facebook has been zero help getting it shut down, even though the person posting from it is clearly misrepresenting who he is.
Some days I'm ready to go back to scraping on cave walls and trading rocks instead of relying on this computer stuff..
John