Always use a strong, unique passphrase for your wallet.
Do you need help against these leaks?
I can provide specific or security checklists based on what you need.
Never keep a wallet.dat on a web-connected server. Use hardware wallets or air-gapped backups.