I have the same problem. I completely understand your plight. I registered for MTNL's broadband two months ago.
i started using it last month. After changing the password, i realised someone has been using my account for about two hours - between 6-8.30 a.m.
Now, i have a Night Unlimited plan. If the thief wants to use it, do so during the time i dont get charged for it. This person tips over the 8 a.m. mark and the downloaded bytes get logged in the Session History.
Initially, it was just 3-4 MB. in the last 4 days...28 & 30 MB.
Changing passwords might deter someone from using your account. But that is temporary, especially when the Register login page is plain HTTP not HTTPS (secure and encrypted).
I am sure MTNL admins (or people within or the broadband guys who MTNL has contracted to provide the service) are using our accounts during their shifts.
I am yet to complain because of my work hours.
But the point I am trying to make is how do we, as consumers, shake companies like MTNL into taking some action? It is my (our) money that runs their bl*dy infrastructure.
We pay our bills on time, we are entitled to an honest (if not better) service.