Hello i nees help

I was scammed by a guy who lied to be a PVU admin and put my passphrase, how secure is my account if they know my passphrase, but not my password? What could I do? I don’t want to resign myself and lose everything