When changing password in the Account Settings page the website should send an email, or some other form of confirmation, to make sure someone isn't hijacking the account. Especially given the fact that credit / debit card information can be on there.